AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications exposes users to potential account compromise through authentication requests, enabling attackers to exploit this via misleading or generic names.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.
AD domain accounts with password not required

Attackers can exploit AD domain accounts with password not required for unauthorized access, potentially leading to credential exposure and misuse.
AD domain account with Kerberos pre-authentication disabled

A domain account without Kerberos pre-authentication protection exposes attackers to offline password cracking opportunities.
Microsoft Entra app with client secrets

A Microsoft Entra app with client secrets increases exposure due to potential secret disclosure and enables attackers to access permissions granted to the service principal.
Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).
Microsoft Entra tenant with unsecure Guest user access permissions

A Microsoft Entra tenant with unsecured Guest user access permissions exposes groups and users to unauthorized enumeration, expanding attacker reconnaissance capabilities.