Microsoft Entra tenant with Privileged Identity Management not being used

A Microsoft Entra tenant without Privileged Identity Management (PIM) exposes powerful roles to immediate access by attackers, escalating privileges and accessing sensitive resources.
Microsoft Entra role with permanent eligible members

A Microsoft Entra role with permanent eligible members exposes administrative privileges to unauthorized access if an account is compromised, enabling attack paths through reconnaissance and persistence.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
Dangerous ACLs expose GPOs applied to privileged group members

Critical: Misconfigured ACLs expose GPOs applied to privileged group members, allowing attackers to execute code on workstations of those accounts through unauthorized access to sensitive settings and permissions.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Dangerous ACLs expose DPAPI key objects

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.
Dangerous ACLs expose Certificate Templates container

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.
AD forest with high numbers of privileged group accounts

A high number of privileged group accounts in an Active Directory forest exposes administrators to unauthorized access and privilege escalation through lateral movement.
Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).