Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Microsoft Entra role with permanent eligible members

A Microsoft Entra role with permanent eligible members exposes administrative privileges to unauthorized access if an account is compromised, enabling attack paths through reconnaissance and persistence.
AD domain allows unprivileged users to add computer accounts

Attackers can exploit AD domain settings to create legitimate-looking computer accounts for non-existent devices, enabling them to bypass security controls and gain unauthorized access.