Microsoft Entra user retrieving Bitlocker keys

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.
Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
AD domain allowing multicast name resolution (LLMNR)
Active Directory domains enabling Multicast Name Resolution (LLMNR) expose networks to spoofing and credential-harvesting attacks via intercepted DNS requests, allowing attackers to gather user credentials or redirect traffic.
NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.