Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.
AD domain controller deployed as a VM without drive encryption

Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest to unauthorized access via compromised virtual machine.
Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
Inactive AD domain controller

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.
Microsoft Entra app with client secrets

A Microsoft Entra app with client secrets increases exposure due to potential secret disclosure and enables attackers to access permissions granted to the service principal.
Microsoft Entra tenant with unsecure Guest user access permissions

A Microsoft Entra tenant with unsecured Guest user access permissions exposes groups and users to unauthorized enumeration, expanding attacker reconnaissance capabilities.
Microsoft Entra tenant with security defaults not enabled

Attackers can use previously obtained credentials for legacy authentication due to a lack of multi-factor authentication and conditional access policy enforcement in an unsecured Microsoft Entra tenant.
Unauthorized certificate addition to Entra ID Enterprise Application

Unauthorized Entra ID Enterprise Application certificates can be added by attackers, allowing them to authenticate without MFA due to compromised credentials.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.
AD domain controller with enabled print spooler

A domain controller with enabled print spooler exposes domain credentials to remote connections, enabling attackers to compromise the domain controller or other systems through Kerberos authentication attacks.