Short-lived privileged AD object

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.
Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.
Computer not resetting its password periodically

A non-expiring password on a computer account may indicate unauthorized access or control, allowing attackers to use pass-through authentication and potentially leading to more serious compromise.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
AD computer using dNSHostName that belongs to another computer account

Attackers can exploit dNSHostName attribute modifications in Active Directory to impersonate computer accounts, compromising certificate-based authentication.
AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Insufficient Active Directory domain controller auditing policy configuration

A missing or inadequate Active Directory domain controller auditing policy configuration exposes your environment to lateral movement attacks.
Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Exchange Online mailbox with SMTP forwarding address

Exchange Online mailbox with an SMTP forwarding address exposes the organization to potential email interception by threat actors.
Guest account with Microsoft Entra role membership

A guest account with Microsoft Entra role membership exposes the environment to potential privilege escalation and external identity exposure through unmanaged identities.