Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
AD computer using dNSHostName that belongs to another computer account

Attackers can exploit dNSHostName attribute modifications in Active Directory to impersonate computer accounts, compromising certificate-based authentication.
AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Insufficient Active Directory domain controller auditing policy configuration

A missing or inadequate Active Directory domain controller auditing policy configuration exposes your environment to lateral movement attacks.
AD domain allows unprivileged users to add computer accounts

Attackers can exploit AD domain settings to create legitimate-looking computer accounts for non-existent devices, enabling them to bypass security controls and gain unauthorized access.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
Dangerous ACLs expose GPOs applied to privileged group members

Critical: Misconfigured ACLs expose GPOs applied to privileged group members, allowing attackers to execute code on workstations of those accounts through unauthorized access to sensitive settings and permissions.
AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.