Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
AD domain controller allowing authentication with keys vulnerable to ROCA
Stale Microsoft Entra guest account

Stale Microsoft Entra guest accounts expose your Entra ID tenant to information collection by attackers through inactive user accounts.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.
Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Exchange Online mailbox with SMTP forwarding address

Exchange Online mailbox with an SMTP forwarding address exposes the organization to potential email interception by threat actors.