Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Service principal promoted to privileged role via OAuth consent attack

Attackers exploit OAuth consent to promote malicious service principals, enabling long-term persistence in Entra ID. Cayosoft Guardian detects and mitigates this threat by monitoring OAuth consent logs and service principal permissions.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

Exchange Organization without mail-flow rules restricting attachments with executables exposes organizations to attack via email-borne malware and scripts.
Microsoft Entra user not registered with MFA

Microsoft Entra user accounts without MFA are exposed to unauthorized access due to lack of identity verification, enabling attackers to gain access through password guessing or theft.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Microsoft Entra application registration with dangling URI

Attackers can exploit dangling Microsoft Entra application registration URIs to obtain user sessions’ authorization tokens, enabling lateral movement or privilege escalation.