Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
AD CS server vulnerable to NTLM relay attacks

An NTLM relay attack exploits the NTLM challenge-response mechanism, allowing attackers to authenticate as legitimate users and gain unauthorized access.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
Modified federation settings in Microsoft Entra domain

Modified federation settings in Microsoft Entra domain expose sensitive access to attackers who can exploit the change for unauthorized access and persistence.
Backup location with unencrypted AD backups

Unencrypted AD backups expose sensitive data to unauthorized access, enabling attackers to gather credentials and plan future attacks.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
AD-integrated DNS zone with WINS forward lookup enabled

AD-integrated DNS zones with WINS forward lookup enabled expose users to forged DNS responses that can compromise account authentication, enabling attackers to bypass authentication or steal credentials.
External trust without SID filtering enabled

External trusts without SID filtering enabled expose Active Directory to spoofed Security Identifiers (SIDs) in access requests, allowing attackers to gain unauthorized access.
Computer with unsupported OS version in AD domain

Outdated OS versions in AD domains expose systems to security vulnerabilities, enabling attackers to exploit unpatched weaknesses.