Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
Microsoft Entra tenant with security defaults not enabled

Attackers can use previously obtained credentials for legacy authentication due to a lack of multi-factor authentication and conditional access policy enforcement in an unsecured Microsoft Entra tenant.
Unauthorized certificate addition to Entra ID Enterprise Application

Unauthorized Entra ID Enterprise Application certificates can be added by attackers, allowing them to authenticate without MFA due to compromised credentials.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.
Entra ID Missing Conditional Access Policy for blocking access for untrusted locations

Entra ID’s missing Conditional Access policy exposes credentials to unauthorized access via untrusted locations.
Microsoft Entra tenant with unsecure access to Azure management

Unsecured Azure management access in Microsoft Entra tenant exposes sensitive resources to unauthorized users, enabling potential privilege escalation through bypassed multifactor authentication (MFA) requirements.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.
Microsoft Entra app with risky write permissions

Microsoft Entra apps with write permissions expose your tenant to unauthorized modifications and data tampering.