Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
AD domain with Operator Groups that are not empty

Attackers can exploit non-empty Operator Groups in an AD domain, gaining unauthorized access and escalating privileges.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.
Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.
Active Directory detect dormant accounts for computers and users

Detecting dormant user and computer accounts in Active Directory helps prevent unauthorized access via stale credentials.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
AD domain with unsecure ESX authentication bypass

VMware ESXi host with unsecure AD authentication exposes attackers to exploit a vulnerability, bypassing access controls and gaining control over the system.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.