Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE) exposes users to extended session duration after privilege elevation or credential compromise, enabling attackers to maintain access to sensitive resources for an extended period.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.