Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
AD no fine-grained password policy found or weak settings detected

Active Directory lacks a fine-grained password policy, exposing attackers to weak passwords and escalated privileges.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
AD computer account that is a member of privileged groups

A compromised AD computer account in a privileged group enables persistent lateral movement within the domain.
AD Domain Controller with non-admin owner

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.