Microsoft Entra tenant where regular users can register applications

High-risk exposure in Microsoft Entra tenant where regular users can register applications, enabling attackers to expand their reach and gain persistence.
AD domain controller not changing its password

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.
The certificate template has a key length of less than 2048 bits

A certificate template with a key length of less than 2048 bits exposes the organization to high-risk cryptographic vulnerabilities, enabling attackers to exploit weaknesses in random number generation and side-channel attacks.
Dangerous ACLs expose certificate containers

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.
Dangerous enrollment permission on authentication certificate templates

Misconfigured certificate templates expose Active Directory Certificate Services to unauthorized users obtaining high-privilege certificates due to excessive enrollment permission.
Privileged Microsoft Entra account not registered for MFA

Privileged Microsoft Entra accounts without multi-factor authentication (MFA) expose organizations to identity-based attacks via password-only authentication.
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Stale Microsoft Entra guest account

Stale Microsoft Entra guest accounts expose your Entra ID tenant to information collection by attackers through inactive user accounts.