Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.
Active Directory detect dormant accounts for computers and users

Detecting dormant user and computer accounts in Active Directory helps prevent unauthorized access via stale credentials.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
AD domain with unsecure ESX authentication bypass

VMware ESXi host with unsecure AD authentication exposes attackers to exploit a vulnerability, bypassing access controls and gaining control over the system.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

Exchange Organization without mail-flow rules restricting attachments with executables exposes organizations to attack via email-borne malware and scripts.
Microsoft Entra user not registered with MFA

Microsoft Entra user accounts without MFA are exposed to unauthorized access due to lack of identity verification, enabling attackers to gain access through password guessing or theft.
Stale administrative account in AD domain

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.
AD domain controller with SMB1 enabled

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.