AD domain with unsecure configuration of Cloud Kerberos Trust

A hybrid AD environment’s unsecure Cloud Kerberos Trust configuration exposes sensitive resources to unauthorized access via Microsoft Entra ID.
AD domain with multiple failed authentication attempts by non-existing users using Kerberos

Multiple failed Kerberos authentication attempts by non-existent users indicate a potential password spraying attack, exposing credentials and permissions.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.
Detected a malicious inbox rule to conceal email in Exchange Online

A malicious inbox rule in Exchange Online conceals emails, aiding Business Email Compromise attacks, exposing your organization to unauthorized data access and financial losses.
Unusual device wipe activity

Bulk device wipes within a short time frame indicate potential unauthorized access or malicious activity, exposing an organization’s devices and data integrity.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE) exposes users to extended session duration after privilege elevation or credential compromise, enabling attackers to maintain access to sensitive resources for an extended period.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.