AD domain with Operator Groups that are not empty

Attackers can exploit non-empty Operator Groups in an AD domain, gaining unauthorized access and escalating privileges.
Active Directory detect dormant accounts for computers and users

Detecting dormant user and computer accounts in Active Directory helps prevent unauthorized access via stale credentials.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

Exchange Organization without mail-flow rules restricting attachments with executables exposes organizations to attack via email-borne malware and scripts.
Microsoft Entra user not registered with MFA

Microsoft Entra user accounts without MFA are exposed to unauthorized access due to lack of identity verification, enabling attackers to gain access through password guessing or theft.
AD forest with recent changes to default security descriptor in schema

Active Directory schema modifications expose attack paths and persistence risks.
AD domain with bulk changes of users

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.
Short-lived privileged AD object

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.
Stale administrative account in AD domain

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.