Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
AD user has a password that matches its sAMAccountName

Predictable password pattern in Active Directory exposes users to brute-force attacks, compromising account security and allowing unauthorized access.
Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Backup location with unencrypted AD backups

Unencrypted AD backups expose sensitive data to unauthorized access, enabling attackers to gather credentials and plan future attacks.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method

Entra ID tenants vulnerable to voice authentication-based MFA fatigue attacks expose users to unauthorized access risk through compromised credentials and permissions.
AD domain with unsecure configuration of Cloud Kerberos Trust

A hybrid AD environment’s unsecure Cloud Kerberos Trust configuration exposes sensitive resources to unauthorized access via Microsoft Entra ID.