AD domain allowing multicast name resolution (LLMNR)
Active Directory domains enabling Multicast Name Resolution (LLMNR) expose networks to spoofing and credential-harvesting attacks via intercepted DNS requests, allowing attackers to gather user credentials or redirect traffic.
Private IP addresses in Entra ID Conditional Access policy
Attackers can misuse private IP addresses in Entra ID Conditional Access policies to evade access control boundaries and gain initial access.
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
Active Directory SMB signing not enforced on domain controller
Active Directory SMB signing not enforced on domain controllers exposes SMB traffic to tampering and relay-style attacks, enabling attackers to bypass authentication and access sensitive data.