AD user has a password that matches its sAMAccountName

Predictable password pattern in Active Directory exposes users to brute-force attacks, compromising account security and allowing unauthorized access.
Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
Modified federation settings in Microsoft Entra domain

Modified federation settings in Microsoft Entra domain expose sensitive access to attackers who can exploit the change for unauthorized access and persistence.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
AD computer with suspicious change of sAMAccountName
A suspicious sAMAccountName change on an AD computer can enable attackers to escalate privileges, compromising domain security through attack paths that exploit administrative scope and credentials.
AD user with identical password
Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.