Microsoft Entra tenant with unsecure delegation of Global Admin role

An unsecure delegation of the Global Admin role in a Microsoft Entra tenant exposes sensitive administrative functions to unauthorized access.
Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications exposes users to potential account compromise through authentication requests, enabling attackers to exploit this via misleading or generic names.
Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).
Microsoft Entra tenant with unsecure Guest user access permissions

A Microsoft Entra tenant with unsecured Guest user access permissions exposes groups and users to unauthorized enumeration, expanding attacker reconnaissance capabilities.
Entra ID Missing Conditional Access Policy for blocking access for untrusted locations

Entra ID’s missing Conditional Access policy exposes credentials to unauthorized access via untrusted locations.
Microsoft Entra tenant with unsecure access to Azure management

Unsecured Azure management access in Microsoft Entra tenant exposes sensitive resources to unauthorized users, enabling potential privilege escalation through bypassed multifactor authentication (MFA) requirements.