Microsoft Entra tenant with recent changes in Cross Tenant Access configuration

Unauthorized access or privilege escalation risk due to misconfigured Entra cross-tenant access synchronization.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Service principal promoted to privileged role via OAuth consent attack

Attackers exploit OAuth consent to promote malicious service principals, enabling long-term persistence in Entra ID. Cayosoft Guardian detects and mitigates this threat by monitoring OAuth consent logs and service principal permissions.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
AD user added to privileged group

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
AD forest with recent changes to default security descriptor in schema

Active Directory schema modifications expose attack paths and persistence risks.
AD domain with bulk changes of users

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.
AD domain with multiple failed authentication attempts via process

Multiple failed authentication attempts via process in an Active Directory domain expose attack paths and allow attackers to obtain initial access or elevate privileges.