Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
Modified federation settings in Microsoft Entra domain

Modified federation settings in Microsoft Entra domain expose sensitive access to attackers who can exploit the change for unauthorized access and persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
AD forest with the Azure SSO computer account not changing its password

Attackers can exploit a misconfigured Azure SSO computer account in an Active Directory forest, allowing them to authenticate as any user with access to Microsoft Entra ID using the static password.
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method

Entra ID tenants vulnerable to voice authentication-based MFA fatigue attacks expose users to unauthorized access risk through compromised credentials and permissions.
AD domain with unsecure configuration of Cloud Kerberos Trust

A hybrid AD environment’s unsecure Cloud Kerberos Trust configuration exposes sensitive resources to unauthorized access via Microsoft Entra ID.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.