AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Dangerous ACLs expose DPAPI key objects

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.
Dangerous ACLs expose Certificate Templates container

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.
AD forest with high numbers of privileged group accounts

A high number of privileged group accounts in an Active Directory forest exposes administrators to unauthorized access and privilege escalation through lateral movement.
AD Domain where Enterprise Key Admins group has full access to the domain

Attackers can exploit a domain group with excessive permissions in Active Directory to perform DCSync attacks and compromise the forest.
AD domain controller using unsecure encryption type

Domain controllers using outdated or insecure encryption types expose sensitive data to attackers, enabling privilege escalation and credential access through Kerberos protocol exploitation.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.
Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.
AD domain controller deployed as a VM without drive encryption

Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest to unauthorized access via compromised virtual machine.