AD forest with anonymous access enabled over Name Service Provider Interface

Anonymous RPC-based binds via Name Service Provider Interface expose AD forest to reconnaissance and initial access.
AD domain controller allowing vulnerable Netlogon secure channel connections

An unauthenticated attacker can exploit a domain controller’s vulnerable Netlogon secure channel connection, changing AD passwords and escalating privileges.
Microsoft Entra application registration with dangling URI

Attackers can exploit dangling Microsoft Entra application registration URIs to obtain user sessions’ authorization tokens, enabling lateral movement or privilege escalation.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.
Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Entra ID tenant without a policy to show geographic location context in Microsoft Authenticator notifications exposes users to authentication requests that may be confirmed by mistake due to lack of contextual information, enabling attackers to gain unauthorized access.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
Microsoft Entra tenant with Privileged Identity Management not being used

A Microsoft Entra tenant without Privileged Identity Management (PIM) exposes powerful roles to immediate access by attackers, escalating privileges and accessing sensitive resources.
Microsoft Entra tenant configured to allow guests to invite other guests

A tenant-wide guest invitation configuration exposes data on other users, enabling attack paths through information gathering.
Insufficient Active Directory domain controller auditing policy configuration

A missing or inadequate Active Directory domain controller auditing policy configuration exposes your environment to lateral movement attacks.