Dangerous ACLs expose GPOs applied to privileged group members

Critical: Misconfigured ACLs expose GPOs applied to privileged group members, allowing attackers to execute code on workstations of those accounts through unauthorized access to sensitive settings and permissions.
AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.
AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.
Dangerous ACLs expose DPAPI key objects

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.
Dangerous ACLs expose Certificate Templates container

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.
AD forest with high numbers of privileged group accounts

A high number of privileged group accounts in an Active Directory forest exposes administrators to unauthorized access and privilege escalation through lateral movement.
AD Domain where Enterprise Key Admins group has full access to the domain

Attackers can exploit a domain group with excessive permissions in Active Directory to perform DCSync attacks and compromise the forest.
AD domain controller using unsecure encryption type

Domain controllers using outdated or insecure encryption types expose sensitive data to attackers, enabling privilege escalation and credential access through Kerberos protocol exploitation.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.