Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.