AD forest with the Azure SSO computer account not changing its password

Attackers can exploit a misconfigured Azure SSO computer account in an Active Directory forest, allowing them to authenticate as any user with access to Microsoft Entra ID using the static password.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
AD forest with Java schema extension

Active Directory forests with Java schema extensions are exposed to malicious code injection through extended attributes, enabling attackers to escalate privileges and execute arbitrary commands.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
AD forest with recent changes to default security descriptor in schema

Active Directory schema modifications expose attack paths and persistence risks.