AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Guest account with Microsoft Entra role membership

A guest account with Microsoft Entra role membership exposes the environment to potential privilege escalation and external identity exposure through unmanaged identities.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.
Inactive AD domain controller

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
AD domain accounts with password not required

Attackers can exploit AD domain accounts with password not required for unauthorized access, potentially leading to credential exposure and misuse.