Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
Device enrolled in Intune but never synced

Devices enrolled in Intune but never synced expose organizations to attack paths through persistence and reconnaissance, highlighting the need for continuous compliance checks.
Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.
Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.
AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
AD-integrated DNS zone with WINS forward lookup enabled

AD-integrated DNS zones with WINS forward lookup enabled expose users to forged DNS responses that can compromise account authentication, enabling attackers to bypass authentication or steal credentials.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.
Regular AD object with unexpected admincount value

Unexpected admincount values in AD objects may indicate unauthorized changes, allowing attackers to evade detection and plan future malicious operations.