Microsoft Entra tenant where regular users can register applications

High-risk exposure in Microsoft Entra tenant where regular users can register applications, enabling attackers to expand their reach and gain persistence.
Microsoft Entra tenant with unsecure configuration of sign-in risk policy

A misconfigured sign-in risk policy in Microsoft Entra Conditional Access exposes users to unauthorized access due to lack of multifactor authentication at Medium or High risk levels.
Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Microsoft Entra tenant where regular users can create Microsoft 365 groups

Regular user group creation exposes tenant-wide access, enabling attackers to collect sensitive information through group membership enumeration.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.
Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Entra ID tenant without a policy to show geographic location context in Microsoft Authenticator notifications exposes users to authentication requests that may be confirmed by mistake due to lack of contextual information, enabling attackers to gain unauthorized access.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.
Microsoft Entra tenant configured to allow guests to invite other guests

A tenant-wide guest invitation configuration exposes data on other users, enabling attack paths through information gathering.
Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization

Microsoft Entra tenant exposes users to unauthorized access due to misconfigured permissions in Microsoft 365 groups, enabling attackers to exploit sensitive resources.