AD forest with anonymous access enabled over Name Service Provider Interface

Anonymous RPC-based binds via Name Service Provider Interface expose AD forest to reconnaissance and initial access.
AD domain controller allowing vulnerable Netlogon secure channel connections

An unauthenticated attacker can exploit a domain controller’s vulnerable Netlogon secure channel connection, changing AD passwords and escalating privileges.
Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.
Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.
User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Microsoft Entra application registration with dangling URI

Attackers can exploit dangling Microsoft Entra application registration URIs to obtain user sessions’ authorization tokens, enabling lateral movement or privilege escalation.
Microsoft Entra app with risky read permissions

Microsoft Entra apps with excessive read permissions expose sensitive data through OAuth 2.0 consent grants.
Microsoft Entra tenant where regular users can create Microsoft 365 groups

Regular user group creation exposes tenant-wide access, enabling attackers to collect sensitive information through group membership enumeration.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.