AD domain account with Kerberos pre-authentication disabled

A domain account without Kerberos pre-authentication protection exposes attackers to offline password cracking opportunities.
Regular AD user account with permissions to modify DNS server objects

A regular AD user with DNS modification permissions exposes a high risk of privilege escalation and unauthorized access through attack paths involving DNS server object modifications.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).
Entra ID Missing Conditional Access Policy for blocking access for untrusted locations

Entra ID’s missing Conditional Access policy exposes credentials to unauthorized access via untrusted locations.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.
AD user with compromised password

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.
AD domain account with password stored using reversible encryption

AD domain accounts with passwords stored using reversible encryption expose credentials to unauthorized parties who can decrypt and sign in anonymously, creating a vulnerability through administrative scope.
AD no fine-grained password policy found or weak settings detected

Active Directory lacks a fine-grained password policy, exposing attackers to weak passwords and escalated privileges.
Privileged AD user not protected against delegation

A high-severity threat where a privileged AD user’s credentials are vulnerable to unauthorized delegation, enabling privilege escalation through Kerberos protocol exploitation.
Privileged AD account password set to never expire

A privileged AD account with a non-expiring password exposes Active Directory resources to persistent attacker access until the password is changed.