AD domain account with password stored using reversible encryption

AD domain accounts with passwords stored using reversible encryption expose credentials to unauthorized parties who can decrypt and sign in anonymously, creating a vulnerability through administrative scope.
AD user account with DES encryption type enabled

Active Directory user accounts using outdated DES encryption type are exposed to brute-force attacks, allowing unauthorized access.