Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Service principal promoted to privileged role via OAuth consent attack

Attackers exploit OAuth consent to promote malicious service principals, enabling long-term persistence in Entra ID. Cayosoft Guardian detects and mitigates this threat by monitoring OAuth consent logs and service principal permissions.
AD user added to privileged group

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.
AD domain with unsecure ESX authentication bypass

VMware ESXi host with unsecure AD authentication exposes attackers to exploit a vulnerability, bypassing access controls and gaining control over the system.
Short-lived privileged AD object

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.