AD user account with DES encryption type enabled

Active Directory user accounts using outdated DES encryption type are exposed to brute-force attacks, allowing unauthorized access.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
AD domain account with unconstrained delegation

An AD domain account with unconstrained delegation exposes service credentials for unauthorized access, enabling attackers to escalate privileges.
Built-in domain Administrator account used recently

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.
AD computer account that is a member of privileged groups

A compromised AD computer account in a privileged group enables persistent lateral movement within the domain.
AD Domain Controller with non-admin owner

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.
Privileged group members with weak password policy

Weak passwords in privileged group members expose accounts to authentication bypass, enabling attackers to gain unauthorized access.