Stale Microsoft Entra device

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.
Microsoft Entra guest account with unredeemed invite

Unredeemed Microsoft Entra guest account invitations can be exploited by attackers to create persistence, increasing risk of credential exposure through authentication and authorization mechanisms.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
Computer not resetting its password periodically

A non-expiring password on a computer account may indicate unauthorized access or control, allowing attackers to use pass-through authentication and potentially leading to more serious compromise.
Microsoft Entra app with risky read permissions

Microsoft Entra apps with excessive read permissions expose sensitive data through OAuth 2.0 consent grants.
Microsoft Entra tenant where regular users can create Microsoft 365 groups

Regular user group creation exposes tenant-wide access, enabling attackers to collect sensitive information through group membership enumeration.
Stale Microsoft Entra service principal

A stale Microsoft Entra service principal can lead to unauthorized access and data breaches if not properly managed, exposing your organization to attack paths through compromised credentials and permissions.
Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization

Microsoft Entra tenant exposes users to unauthorized access due to misconfigured permissions in Microsoft 365 groups, enabling attackers to exploit sensitive resources.