Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
The certificate template has a key length of less than 2048 bits

A certificate template with a key length of less than 2048 bits exposes the organization to high-risk cryptographic vulnerabilities, enabling attackers to exploit weaknesses in random number generation and side-channel attacks.
Dangerous enrollment permission on authentication certificate templates

Misconfigured certificate templates expose Active Directory Certificate Services to unauthorized users obtaining high-privilege certificates due to excessive enrollment permission.