Stale privileged Microsoft Entra user account

A stale privileged Microsoft Entra user account exposes sensitive access and increases attacker capability due to compromised credentials.
Privileged Microsoft Entra account synced from on-premise

Attackers can access Microsoft Entra resources with elevated permissions due to direct membership in administrative roles from a compromised on-premises account synced from Active Directory.
Microsoft Entra tenant with unsecure configuration of sign-in risk policy

A misconfigured sign-in risk policy in Microsoft Entra Conditional Access exposes users to unauthorized access due to lack of multifactor authentication at Medium or High risk levels.
Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
AD domain with Operator Groups that are not empty

Attackers can exploit non-empty Operator Groups in an AD domain, gaining unauthorized access and escalating privileges.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.