Private IP addresses in Entra ID Conditional Access policy
Attackers can misuse private IP addresses in Entra ID Conditional Access policies to evade access control boundaries and gain initial access.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
Microsoft Entra tenant where regular users can register applications

High-risk exposure in Microsoft Entra tenant where regular users can register applications, enabling attackers to expand their reach and gain persistence.
Privileged Microsoft Entra account not registered for MFA

Privileged Microsoft Entra accounts without multi-factor authentication (MFA) expose organizations to identity-based attacks via password-only authentication.
Stale Microsoft Entra guest account

Stale Microsoft Entra guest accounts expose your Entra ID tenant to information collection by attackers through inactive user accounts.
Stale privileged Microsoft Entra user account

A stale privileged Microsoft Entra user account exposes sensitive access and increases attacker capability due to compromised credentials.
Microsoft Entra tenant with bulk changes of groups

Bulk group changes in your Microsoft Entra tenant may indicate unauthorized access or service disruptions.
Privileged Microsoft Entra account synced from on-premise

Attackers can access Microsoft Entra resources with elevated permissions due to direct membership in administrative roles from a compromised on-premises account synced from Active Directory.
Microsoft Entra tenant with unsecure configuration of sign-in risk policy

A misconfigured sign-in risk policy in Microsoft Entra Conditional Access exposes users to unauthorized access due to lack of multifactor authentication at Medium or High risk levels.
Microsoft Entra tenant with recent changes in Cross Tenant Access configuration

Unauthorized access or privilege escalation risk due to misconfigured Entra cross-tenant access synchronization.