Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
AD domain with restored domain controllers

Attackers can modify user account access and evade detection through restored domain controllers in Active Directory, allowing unauthorized password resets or group membership modifications.
AD forest with Java schema extension

Active Directory forests with Java schema extensions are exposed to malicious code injection through extended attributes, enabling attackers to escalate privileges and execute arbitrary commands.
Microsoft Entra tenant with unsecure app consent policy configuration

A tenant policy allowing any user to grant app access without admin consent exposes users to consent phishing via unsecured app permissions.
Computer with unsupported OS version in AD domain

Outdated OS versions in AD domains expose systems to security vulnerabilities, enabling attackers to exploit unpatched weaknesses.
Stale Microsoft Entra device

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.
Microsoft Entra guest account with unredeemed invite

Unredeemed Microsoft Entra guest account invitations can be exploited by attackers to create persistence, increasing risk of credential exposure through authentication and authorization mechanisms.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
AD user with identical password
Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.