External trust without SID filtering enabled

External trusts without SID filtering enabled expose Active Directory to spoofed Security Identifiers (SIDs) in access requests, allowing attackers to gain unauthorized access.
Active Directory password in Group Policy Preferences (GPP) compromise

Active Directory password exposure in Group Policy Preferences (GPP) XML files allows attackers to decrypt passwords and access privileged accounts or systems.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
AD domain with restored domain controllers

Attackers can modify user account access and evade detection through restored domain controllers in Active Directory, allowing unauthorized password resets or group membership modifications.
AD forest with Java schema extension

Active Directory forests with Java schema extensions are exposed to malicious code injection through extended attributes, enabling attackers to escalate privileges and execute arbitrary commands.
Privileged AD user with failed logon attempts

A Privileged AD user with failed logon attempts may indicate an unauthorized access attempt against a high-value domain account, exposing attack paths and administrative scope.
Computer with unsupported OS version in AD domain

Outdated OS versions in AD domains expose systems to security vulnerabilities, enabling attackers to exploit unpatched weaknesses.
AD domain with bulk changes of groups

Active Directory bulk group changes can indicate malicious activity or errors, leading to service disruptions and unauthorized access.
AD domain with bulk changes of computers

Active Directory bulk changes can indicate unauthorized modifications or mistakes, impacting service availability and exposing attack paths.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.