Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Unusual device wipe activity

Bulk device wipes within a short time frame indicate potential unauthorized access or malicious activity, exposing an organization’s devices and data integrity.
Device enrolled in Intune but never synced

Devices enrolled in Intune but never synced expose organizations to attack paths through persistence and reconnaissance, highlighting the need for continuous compliance checks.
Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.
Stale Microsoft Entra device

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.