Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Private IP addresses in Entra ID Conditional Access policy
Attackers can misuse private IP addresses in Entra ID Conditional Access policies to evade access control boundaries and gain initial access.
Entra object created by unusual Initiator
Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.
Stale privileged Microsoft Entra user account

A stale privileged Microsoft Entra user account exposes sensitive access and increases attacker capability due to compromised credentials.
Microsoft Entra tenant with bulk changes of groups

Bulk group changes in your Microsoft Entra tenant may indicate unauthorized access or service disruptions.
Microsoft Entra tenant with unsecure configuration of sign-in risk policy

A misconfigured sign-in risk policy in Microsoft Entra Conditional Access exposes users to unauthorized access due to lack of multifactor authentication at Medium or High risk levels.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.