Misconfigurations Remain the Open Door for Attackers
Article content
Across a large number of security reviews, we keep seeing the same thing. Organizations rarely go down because of a spectacular, advanced attack. They go down because of things that have been known for a long time and were simply never fixed: wrong settings, delayed basic measures, assumptions that no longer hold. An attacker doesn't need to invent much. They just walk down the row of doors and check which ones are open.
The examples below come from two types of research: our security tests of internal infrastructure, typically involving Active Directory, and our cloud security reviews of Microsoft 365 environments. They have been anonymized and summarized at a high level.
The easy way in
In nearly 40% of internal tests involving Active Directory, we were able to fully take over the domain. That didn't require an unknown vulnerability; the techniques have been known for years. Print Spooler abuse, Kerberoasting, password spraying, credentials sitting in plain text in a file on the network.
Passwords remain a weak spot. On average, we cracked 34% of hashes, with a median of 29% and outliers up to 74%. In more than 90% of pentests, we succeeded in executing code on workstations, giving an attacker all the room they need to move further.
The internal network is often less protected than the perimeter. The wired network is implicitly trusted, and segmentation in practice tends to be looser than on paper. What looks like a boundary on a diagram doesn't always hold up in a test.
Security you're already paying for
We see the same pattern in cloud security reviews. The problem isn't Microsoft 365 itself, but what goes wrong in Microsoft 365 environments and other cloud environments due to incorrect or unused settings. In roughly two-thirds of organizations, the identity basics aren't in order: legacy authentication is still enabled and MFA isn't enforced everywhere.
In almost every environment, we found default settings that make phishing unnecessarily easy. Device Code Flow is a good example, and it's not the only one.
What stands out is that most of these measures are already included in the license. You don't need to buy them, just switch them on. That open door is often closed with a setting, not a budget.
Too much access, too little visibility
Two findings reinforce each other. In a large share of Microsoft 365 environments, sensitive information in SharePoint was more broadly accessible than intended. Usually not through deliberate public sharing, but because groups turn out to be far larger in practice than assumed. Permissions pile up as an organization grows, without anyone making that choice consciously.
At the same time, 68% of environments lack central detection through a SOC or SIEM. Logs usually exist, but nobody looks at them structurally and signals never come together. As a result, an incident often only becomes clear after the fact, once it has already happened.
Broad access to sensitive data combined with little visibility into how it's used: that's exactly where an attacker moves undisturbed.
What happens inside matters more than you think
Internal and cloud are not separate worlds. In trusted locations, such as the office network, organizations often loosen identity requirements. Understandable, until someone actually gets in. At that point the assumption no longer holds: the cloud settings haven't changed, but they no longer do their job. A weak spot on the inside carries straight through to the outside.
AI is shrinking your margin
Much of this was already true a few years ago. What's changed is the pace. AI shortens the time between a vulnerability becoming known and it being exploited at scale. The room to patch calmly has gotten smaller.
That's exactly why maintaining your existing on-prem and hybrid environment matters more, not less. It doesn't produce a visible project or a new dashboard to show off. But it's the first thing an attacker looks at, and where you lose time the fastest. Good, secure operations remain daily work.
Outsourcing shifts the work, not the risk
Many organizations place management with an external party. A fine choice, and often sensible. In practice, though, we see that not all available measures are actually used, and that a supplier doesn't always feel the urgency around patching and remediation the way the client does.
You can outsource the work, but the risk stays yours. So ask your supplier sharp questions. Which security features are actually turned on? How fast do you patch after a report? Where do the signals come together, and who looks at them? Whoever pays for a service is entitled to a concrete, demonstrable answer.
Where to start
Most of this is within your own control. Turn on what you already have: disable legacy authentication, enforce MFA everywhere, and restrict the settings that make phishing easy. Maintain your existing environment as if abuse happens fast, because it does. Give people access only to what they need. And make sure your detection comes together in one place, so you catch an incident at the start instead of after it's over.
None of this is spectacular. That's exactly the point: an attacker starts with the simple things, so that's where you should start too. If you want to know where things stand in your environment, we're happy to take a look with you.
About the authors
Jean de Cuba & Ramin Töpfer
Offensive Security Specialists at DEFION. They carry out pentests and cloud security reviews of internal infrastructure and Microsoft 365 environments, and translate findings into concrete remediation actions.
Related services
Are your Active Directory and Microsoft 365 environment properly configured?
DEFION tests your internal infrastructure and cloud environment for exactly the misconfigurations attackers find first, and helps with concrete, actionable fixes.
Internal Pentest
Test how far an attacker gets on your internal network and Active Directory
Cloud Security Assessment
Identify misconfigurations and unused security features in Microsoft 365
Managed Detection & Response
Central detection via SOC/SIEM, so signals come together instead of staying scattered
Security Advisory
Strategic advice on identity management, access control, and detection setup
®