Unusual device wipe activity

Active Directory

Bulk device wipes within a short time frame indicate potential unauthorized access or malicious activity, exposing an organization’s devices and data integrity.

Device enrolled in Intune but never synced

Active Directory

Devices enrolled in Intune but never synced expose organizations to attack paths through persistence and reconnaissance, highlighting the need for continuous compliance checks.

Microsoft Entra user with authentication phone details modified by another user

Active Directory

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.

Microsoft Entra user retrieving Bitlocker keys

Active Directory

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.

Stale Microsoft Entra device

Entra ID

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.