Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications exposes users to potential account compromise through authentication requests, enabling attackers to exploit this via misleading or generic names.
AD domain controller deployed as a VM without drive encryption

Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest to unauthorized access via compromised virtual machine.
Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.
Inactive AD domain controller

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
AD domain accounts with password not required

Attackers can exploit AD domain accounts with password not required for unauthorized access, potentially leading to credential exposure and misuse.
AD domain account with Kerberos pre-authentication disabled

A domain account without Kerberos pre-authentication protection exposes attackers to offline password cracking opportunities.
Microsoft Entra app with client secrets

A Microsoft Entra app with client secrets increases exposure due to potential secret disclosure and enables attackers to access permissions granted to the service principal.