Microsoft Entra user not registered with MFA

Active Directory

Microsoft Entra user accounts without MFA are exposed to unauthorized access due to lack of identity verification, enabling attackers to gain access through password guessing or theft.

AD domain with bulk changes of users

Active Directory

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.

Short-lived privileged AD object

Active Directory

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.

Stale administrative account in AD domain

Active Directory

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.