Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.
Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.
AD user added to privileged group

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.
AD domain with unsecure ESX authentication bypass

VMware ESXi host with unsecure AD authentication exposes attackers to exploit a vulnerability, bypassing access controls and gaining control over the system.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
AD domain with multiple failed authentication attempts via process

Multiple failed authentication attempts via process in an Active Directory domain expose attack paths and allow attackers to obtain initial access or elevate privileges.
AD domain controller with SMB1 enabled

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.