Dangerous enrollment permission on authentication certificate templates

Misconfigured certificate templates expose Active Directory Certificate Services to unauthorized users obtaining high-privilege certificates due to excessive enrollment permission.
Privileged Microsoft Entra account not registered for MFA

Privileged Microsoft Entra accounts without multi-factor authentication (MFA) expose organizations to identity-based attacks via password-only authentication.
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Stale Microsoft Entra guest account

Stale Microsoft Entra guest accounts expose your Entra ID tenant to information collection by attackers through inactive user accounts.
Stale privileged Microsoft Entra user account

A stale privileged Microsoft Entra user account exposes sensitive access and increases attacker capability due to compromised credentials.
Privileged Microsoft Entra account synced from on-premise

Attackers can access Microsoft Entra resources with elevated permissions due to direct membership in administrative roles from a compromised on-premises account synced from Active Directory.
Microsoft Entra tenant with unsecure configuration of sign-in risk policy

A misconfigured sign-in risk policy in Microsoft Entra Conditional Access exposes users to unauthorized access due to lack of multifactor authentication at Medium or High risk levels.
Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.