Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Regular AD user account with permissions to modify DNS server objects

A regular AD user with DNS modification permissions exposes a high risk of privilege escalation and unauthorized access through attack paths involving DNS server object modifications.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).
Microsoft Entra tenant with unsecure Guest user access permissions

A Microsoft Entra tenant with unsecured Guest user access permissions exposes groups and users to unauthorized enumeration, expanding attacker reconnaissance capabilities.
Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
Microsoft Entra tenant with security defaults not enabled

Attackers can use previously obtained credentials for legacy authentication due to a lack of multi-factor authentication and conditional access policy enforcement in an unsecured Microsoft Entra tenant.
Unauthorized certificate addition to Entra ID Enterprise Application

Unauthorized Entra ID Enterprise Application certificates can be added by attackers, allowing them to authenticate without MFA due to compromised credentials.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.
Entra ID Missing Conditional Access Policy for blocking access for untrusted locations

Entra ID’s missing Conditional Access policy exposes credentials to unauthorized access via untrusted locations.
Microsoft Entra tenant with unsecure access to Azure management

Unsecured Azure management access in Microsoft Entra tenant exposes sensitive resources to unauthorized users, enabling potential privilege escalation through bypassed multifactor authentication (MFA) requirements.