Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Entra ID tenant without a policy to show geographic location context in Microsoft Authenticator notifications exposes users to authentication requests that may be confirmed by mistake due to lack of contextual information, enabling attackers to gain unauthorized access.
Stale Microsoft Entra service principal

A stale Microsoft Entra service principal can lead to unauthorized access and data breaches if not properly managed, exposing your organization to attack paths through compromised credentials and permissions.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.
Microsoft Entra tenant with Privileged Identity Management not being used

A Microsoft Entra tenant without Privileged Identity Management (PIM) exposes powerful roles to immediate access by attackers, escalating privileges and accessing sensitive resources.