Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Microsoft Entra tenant with unsecure delegation of Global Admin role

An unsecure delegation of the Global Admin role in a Microsoft Entra tenant exposes sensitive administrative functions to unauthorized access.
Exchange Online mailbox with SMTP forwarding address

Exchange Online mailbox with an SMTP forwarding address exposes the organization to potential email interception by threat actors.
Guest account with Microsoft Entra role membership

A guest account with Microsoft Entra role membership exposes the environment to potential privilege escalation and external identity exposure through unmanaged identities.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
Dangerous ACLs expose GPOs applied to privileged group members

Critical: Misconfigured ACLs expose GPOs applied to privileged group members, allowing attackers to execute code on workstations of those accounts through unauthorized access to sensitive settings and permissions.
AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.
AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.
Dangerous ACLs expose DPAPI key objects

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.