Compromised Credentials: Stolen usernames and passwords are among the most common and dangerous threats.
- Excessive Privileges: Users or accounts with more access rights than necessary for their roles. Bad practices include entitlement creep, cloning, and default roles.
- Partially Offboarded Former Employees: Ex-employees retain some access after leaving the organization (e.g., SaaS accounts, custom apps).
- Contractors Retaining Access: Third-party contractors keep access rights after their engagement ends.
- MFA Bombing/Fatigue Attacks: Hackers overwhelm users with multi-factor authentication requests to trick them into granting access.
- Corporate Account Takeovers: Attackers gain control of highly-privileged corporate accounts.
- Privilege Escalation Paths: Vulnerabilities allowing attackers to increase their access rights.
- Non-Human Identities / Service Accounts: Poorly managed non-human accounts with extensive privileges.
- Access via Nested Groups in AD/Azure: Complex group structures in AD and Azure AD lead to unintended access.
- Misconfigurations in Identity Providers (IdPs): Security gaps arising from incorrect setup of identity management systems