<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Indicators of Exposure</title>
        <link>https://www.tenable.com/indicators/feeds?type=ioe</link>
        <description>获取最新版 Indicators of Exposure 更新</description>
        <lastBuildDate>Sat, 18 Apr 2026 08:20:46 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>指标</generator>
        <image>
            <title>Indicators of Exposure</title>
            <url>https://www.tenable.com/themes/custom/tenable/img/favicons/apple-touch-icon.png</url>
            <link>https://www.tenable.com/indicators/feeds?type=ioe</link>
        </image>
        <copyright>版权 2026 Tenable, Inc. 保留所有权利。</copyright>
        <atom:link href="https://www.tenable.com/indicators/feeds?type=ioe" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[动态对象错误配置和使用]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>动态对象错误配置和使用</p>

      <h3>描述</h3>
      <p>检测动态对象及其相关的不安全配置。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS">https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[BadSuccessor 存在危险的 dMSA 权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>BadSuccessor 存在危险的 dMSA 权限</p>

      <h3>描述</h3>
      <p>BadSuccessor 是 Windows Server 2025 中可利用 dMSA 的 Active Directory 特权提升缺陷，让攻击者可以操纵帐户链接，并可能入侵域。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR">https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[非必要组]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>非必要组</p>

      <h3>描述</h3>
      <p>验证没有空组或组只包含单个成员。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP">https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[敏感 Exchange 权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>敏感 Exchange 权限</p>

      <h3>描述</h3>
      <p>识别影响 Exchange 资源或已分配给 Exchange 组的潜在不安全权限。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[不受支持或过时的 Exchange 服务器]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>不受支持或过时的 Exchange 服务器</p>

      <h3>描述</h3>
      <p>检测到 Microsoft 不再支持的过时 Exchange 服务器，以及缺少最新累积更新的服务器。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危险的 Exchange 错误配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>危险的 Exchange 错误配置</p>

      <h3>描述</h3>
      <p>列出影响 Exchange 资源或其底层 Active Directory 架构对象的错误配置。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[混合 Entra ID 信息]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>混合 Entra ID 信息</p>

      <h3>描述</h3>
      <p>从本地 Active Directory 环境收集已与 Microsoft Entra ID 同步的资源有关的信息，如混合用户和计算机等。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE">https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Exchange 组成员]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>Exchange 组成员</p>

      <h3>描述</h3>
      <p>敏感 Exchange 组中的异常帐户</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[服务帐户配置错误]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>服务帐户配置错误</p>

      <h3>描述</h3>
      <p>显示域服务帐户中的潜在配置错误。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT">https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[冲突的安全主体]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-CONFLICTED-OBJECTS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-CONFLICTED-OBJECTS</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>冲突的安全主体</p>

      <h3>描述</h3>
      <p>请检查是否有重复（冲突）的用户、计算机或组。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-CONFLICTED-OBJECTS">https://www.tenable.com/indicators/ioe/ad/C-CONFLICTED-OBJECTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Shadow Credentials]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>Shadow Credentials</p>

      <h3>描述</h3>
      <p>在“Windows Hello for Business”功能及其相关密钥凭据中检测到 Shadow Credentials 后门程序和配置错误。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS">https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已启用来宾帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GUEST-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GUEST-ACCOUNT</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>已启用来宾帐户</p>

      <h3>描述</h3>
      <p>检查内置的来宾帐户是否已禁用。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-GUEST-ACCOUNT">https://www.tenable.com/indicators/ioe/ad/C-GUEST-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[托管服务帐户中危险的错误配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>托管服务帐户中危险的错误配置</p>

      <h3>描述</h3>
      <p>确保托管服务帐户 (MSAs) 已部署和正确配置。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE">https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已同步到 Microsoft Entra ID 的特权 AD 用户帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-PRIV-SYNC</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-PRIV-SYNC</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>已同步到 Microsoft Entra ID 的特权 AD 用户帐户</p>

      <h3>描述</h3>
      <p>检查特权 Active Directory 用户帐户是否已同步到 Microsoft Entra ID。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-PRIV-SYNC">https://www.tenable.com/indicators/ioe/ad/C-AAD-PRIV-SYNC</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权身份验证孤岛配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AUTH-SILO</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AUTH-SILO</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>特权身份验证孤岛配置</p>

      <h3>描述</h3>
      <p>有关为特权（第 0 层）帐户配置身份验证孤岛的分步指南。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-AUTH-SILO">https://www.tenable.com/indicators/ioe/ad/C-AUTH-SILO</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[允许不安全的动态 DNS 区域更新]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-UPDATES</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-UPDATES</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>允许不安全的动态 DNS 区域更新</p>

      <h3>描述</h3>
      <p>检查 DNS 服务器配置是否禁止不安全的动态 DNS 区域更新。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-UPDATES">https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-UPDATES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危险的 WSUS 错误配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>危险的 WSUS 错误配置</p>

      <h3>描述</h3>
      <p>列出了与 Windows Server Update Services (WSUS) 相关的错误配置参数。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING">https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[属性集的完整性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>属性集的完整性</p>

      <h3>描述</h3>
      <p>检查属性集的完整性并验证权限</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY">https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危险的 SYSVOL 复制配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>危险的 SYSVOL 复制配置</p>

      <h3>描述</h3>
      <p>检查“分布式文件系统复制”(DFS-R) 机制是否替换了“文件复制服务”(FRS)。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG">https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[检测到密码弱点]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>检测到密码弱点</p>

      <h3>描述</h3>
      <p>验证可能会加剧 Active Directory 帐户漏洞的密码中的缺陷。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[针对勒索软件的加固不足]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>针对勒索软件的加固不足</p>

      <h3>描述</h3>
      <p>确保域实现了针对勒索软件的加固措施。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING">https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危险的 ADCS 错误配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>危险的 ADCS 错误配置</p>

      <h3>描述</h3>
      <p>列出与 Active Directory 证书服务 (AD CS) 公钥基础设施 (PKI) 有关、危险的权限以及错误配置的参数。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS">https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GPO 执行的合理性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>GPO 执行的合理性</p>

      <h3>描述</h3>
      <p>验证应用于域计算机的组策略对象 (GPO) 是否健全。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY">https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权用户登录限制]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ADMIN-RESTRICT-AUTH</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ADMIN-RESTRICT-AUTH</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>特权用户登录限制</p>

      <h3>描述</h3>
      <p>检查是否存在可连接到低特权计算机，从而导致凭据盗窃风险的特权用户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ADMIN-RESTRICT-AUTH">https://www.tenable.com/indicators/ioe/ad/C-ADMIN-RESTRICT-AUTH</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[不安全的 Netlogon 协议配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-NETLOGON-SECURITY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-NETLOGON-SECURITY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>不安全的 Netlogon 协议配置</p>

      <h3>描述</h3>
      <p>CVE-2020-1472（“Zerologon”）会影响 Netlogon 协议并允许提升特权</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-NETLOGON-SECURITY">https://www.tenable.com/indicators/ioe/ad/C-NETLOGON-SECURITY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[易受攻击的 Credential Roaming 相关属性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-CREDENTIAL-ROAMING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-CREDENTIAL-ROAMING</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>易受攻击的 Credential Roaming 相关属性</p>

      <h3>描述</h3>
      <p>Credential roaming 属性易受攻击，因此，攻击者可以读取相关受用户保护的密钥。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-CREDENTIAL-ROAMING">https://www.tenable.com/indicators/ioe/ad/C-CREDENTIAL-ROAMING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[潜在明文密码]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-CLEARTEXT-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-CLEARTEXT-PASSWORD</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>潜在明文密码</p>

      <h3>描述</h3>
      <p>检查域用户可读属性中包含潜在明文密码的对象。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-CLEARTEXT-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-CLEARTEXT-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[存在危险的敏感特权]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>存在危险的敏感特权</p>

      <h3>描述</h3>
      <p>识别配置错误的敏感特权，这些特权会降低目录基础设施的安全性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES">https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[帐户上的映射证书]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>帐户上的映射证书</p>

      <h3>描述</h3>
      <p>确保没有弱证书映射被分配给对象。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER">https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[没有计算机加固 GPO 的域]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPO-HARDENING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPO-HARDENING</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>没有计算机加固 GPO 的域</p>

      <h3>描述</h3>
      <p>检查域中是否部署了加固 GPO。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPO-HARDENING">https://www.tenable.com/indicators/ioe/ad/C-GPO-HARDENING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未使用 Protected Users 组]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>未使用 Protected Users 组</p>

      <h3>描述</h3>
      <p>验证是否有特权用户不是 Protected Users 组成员。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED">https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可能使用空密码的帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>可能使用空密码的帐户</p>

      <h3>描述</h3>
      <p>识别允许使用空密码的用户帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[允许将计算机加入到域的用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>允许将计算机加入到域的用户</p>

      <h3>描述</h3>
      <p>确认普通用户无法将外部计算机加入到域。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS">https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft Entra Seamless SSO 帐户密码的上次更改]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-SSO-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-SSO-PASSWORD</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>Microsoft Entra Seamless SSO 帐户密码的上次更改</p>

      <h3>描述</h3>
      <p>确保定期更改 Microsoft Entra Seamless SSO 帐户密码。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-SSO-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-AAD-SSO-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[AD 架构中存在危险的权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>AD 架构中存在危险的权限</p>

      <h3>描述</h3>
      <p>列出被认为存在异常且可能提供持久性方法的架构条目。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA">https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[使用旧密码的用户帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>使用旧密码的用户帐户</p>

      <h3>描述</h3>
      <p>检查 Active Directory 中所有处于活动状态的帐户密码是否定期更新，以减少凭据被盗的风险。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[验证与 Microsoft Entra Connect 帐户相关的权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>验证与 Microsoft Entra Connect 帐户相关的权限</p>

      <h3>描述</h3>
      <p>确保在 Microsoft Entra Connect 帐户上设置的权限是合理的</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT">https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[由非法用户管理的域控制器]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>由非法用户管理的域控制器</p>

      <h3>描述</h3>
      <p>某些域控制器可以由非管理用户管理，这是访问权限存在风险所致。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[对用户应用弱密码策略]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>对用户应用弱密码策略</p>

      <h3>描述</h3>
      <p>一些应用于特定用户帐户的密码策略不够强，可能会导致凭据被盗。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[验证敏感 GPO 和文件权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>验证敏感 GPO 和文件权限</p>

      <h3>描述</h3>
      <p>确保分配给链接到敏感容器（如域控制器或组织单位）的 GPO 对象和文件的权限是适当且安全的。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[采用不安全后向兼容配置的域]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DSHEURISTICS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DSHEURISTICS</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>采用不安全后向兼容配置的域</p>

      <h3>描述</h3>
      <p>dsHeuristics 属性可以修改 AD 行为，但部分字段为安全敏感字段，会带来安全风险。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DSHEURISTICS">https://www.tenable.com/indicators/ioe/ad/C-DSHEURISTICS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[域的功能级别已过时]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DOMAIN-FUNCTIONAL-LEVEL</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DOMAIN-FUNCTIONAL-LEVEL</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>域的功能级别已过时</p>

      <h3>描述</h3>
      <p>检查域或林的功能级别是否正确无误，这将决定高级功能和安全选项的可用性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DOMAIN-FUNCTIONAL-LEVEL">https://www.tenable.com/indicators/ioe/ad/C-DOMAIN-FUNCTIONAL-LEVEL</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[本地管理帐户管理]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-LAPS-UNSECURE-CONFIG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-LAPS-UNSECURE-CONFIG</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>本地管理帐户管理</p>

      <h3>描述</h3>
      <p>确保使用 LAPS 对本地管理帐户进行安全的集中管理。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-LAPS-UNSECURE-CONFIG">https://www.tenable.com/indicators/ioe/ad/C-LAPS-UNSECURE-CONFIG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[用户帐户的 Kerberos 配置]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-KERBEROS-CONFIG-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-KERBEROS-CONFIG-ACCOUNT</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>用户帐户的 Kerberos 配置</p>

      <h3>描述</h3>
      <p>检测使用弱 Kerberos 配置的帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-KERBEROS-CONFIG-ACCOUNT">https://www.tenable.com/indicators/ioe/ad/C-KERBEROS-CONFIG-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[允许类似 DCSync 攻击的根对象权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>允许类似 DCSync 攻击的根对象权限</p>

      <h3>描述</h3>
      <p>检查根对象上是否存在可使未经授权的用户窃取身份验证凭据的不安全权限。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[使用 Windows 2000 以前版本兼容访问控制的帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>使用 Windows 2000 以前版本兼容访问控制的帐户</p>

      <h3>描述</h3>
      <p>检查是否存在可以绕过安全措施的 Windows 2000 以前版本兼容访问组的帐户成员。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS">https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权组中的禁用帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DISABLED-ACCOUNTS-PRIV-GROUPS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DISABLED-ACCOUNTS-PRIV-GROUPS</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>特权组中的禁用帐户</p>

      <h3>描述</h3>
      <p>已停用的帐户不应继续留在特权组中。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DISABLED-ACCOUNTS-PRIV-GROUPS">https://www.tenable.com/indicators/ioe/ad/C-DISABLED-ACCOUNTS-PRIV-GROUPS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[运行过时操作系统的计算机]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-OBSOLETE-SYSTEMS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-OBSOLETE-SYSTEMS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>运行过时操作系统的计算机</p>

      <h3>描述</h3>
      <p>识别 Microsoft 不再支持且会增加基础结构安全漏洞的过时系统。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-OBSOLETE-SYSTEMS">https://www.tenable.com/indicators/ioe/ad/C-OBSOLETE-SYSTEMS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[具有存在危险的 SID History 属性的帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>具有存在危险的 SID History 属性的帐户</p>

      <h3>描述</h3>
      <p>使用 SID history 属性中的特权 SID 检查用户/计算机帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY">https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[在 Active Directory PKI 中使用弱加密算法]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>在 Active Directory PKI 中使用弱加密算法</p>

      <h3>描述</h3>
      <p>标识部署在内部 Active Directory PKI 上的根证书中所使用的弱加密算法。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO">https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[最近使用了默认管理员帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ADM-ACC-USAGE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ADM-ACC-USAGE</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>最近使用了默认管理员帐户</p>

      <h3>描述</h3>
      <p>检查内置管理员帐户的近期使用情况。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ADM-ACC-USAGE">https://www.tenable.com/indicators/ioe/ad/C-ADM-ACC-USAGE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[用户主要组]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>用户主要组</p>

      <h3>描述</h3>
      <p>验证用户的主要组是否未发生变化</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID">https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危险的 Kerberos 委派]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>危险的 Kerberos 委派</p>

      <h3>描述</h3>
      <p>检查是否存在未经授权的 Kerberos 委派，确保特权用户免受其影响。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG">https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可逆密码]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>可逆密码</p>

      <h3>描述</h3>
      <p>验证是否未启用以可逆格式存储密码的选项。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS">https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GPO 中的可逆密码]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>GPO 中的可逆密码</p>

      <h3>描述</h3>
      <p>检查 GPO 首选项是否允许使用可逆格式的密码。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO">https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[确保 SDProp 一致性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>确保 SDProp 一致性</p>

      <h3>描述</h3>
      <p>控制 AdminSDHolder 对象处于干净状态。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[KRBTGT 帐户上次更改密码的时间]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>KRBTGT 帐户上次更改密码的时间</p>

      <h3>描述</h3>
      <p>查找超过建议间隔没有更改密码的 KRBTGT 帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[本机管理组成员]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-NATIVE-ADM-GROUP-MEMBERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-NATIVE-ADM-GROUP-MEMBERS</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>本机管理组成员</p>

      <h3>描述</h3>
      <p>Active Directory 本机管理组中的异常帐户</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-NATIVE-ADM-GROUP-MEMBERS">https://www.tenable.com/indicators/ioe/ad/C-NATIVE-ADM-GROUP-MEMBERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[运行 Kerberos 服务的特权帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>运行 Kerberos 服务的特权帐户</p>

      <h3>描述</h3>
      <p>检测具有服务主体名称 (SPN) 属性的高特权帐户，因为该属性会危害帐户安全。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN">https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[标准用户中设置的 AdminCount 属性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ADMINCOUNT-ACCOUNT-PROPS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ADMINCOUNT-ACCOUNT-PROPS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>标准用户中设置的 AdminCount 属性</p>

      <h3>描述</h3>
      <p>检查已停用帐户是否具有 adminCount 属性，从而造成难以管理的权限问题。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-ADMINCOUNT-ACCOUNT-PROPS">https://www.tenable.com/indicators/ioe/ad/C-ADMINCOUNT-ACCOUNT-PROPS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[休眠帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>休眠帐户</p>

      <h3>描述</h3>
      <p>检测可带来安全风险的未使用的休眠帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS">https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[存在危险的信任关系]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>存在危险的信任关系</p>

      <h3>描述</h3>
      <p>识别配置错误的信任关系属性，这些属性会降低目录基础结构的安全性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP">https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[密码永不过期的帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-DONT-EXPIRE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-DONT-EXPIRE</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>密码永不过期的帐户</p>

      <h3>描述</h3>
      <p>检查是否存在这样的帐户，其 userAccountControl 属性中包含允许无限期使用相同密码以绕过密码更新策略的 DONT_EXPIRE_PASSWORD 属性标记。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-DONT-EXPIRE">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-DONT-EXPIRE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未链接、已禁用或孤立的 GPO]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPOLICY-DISABLED-UNLINKED</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPOLICY-DISABLED-UNLINKED</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>未链接、已禁用或孤立的 GPO</p>

      <h3>描述</h3>
      <p>未使用或禁用的 GPO 会降低目录性能和 RSoP 计算速度，并可能导致安全策略混淆。误将它们重新激活可能会削弱现有策略。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPOLICY-DISABLED-UNLINKED">https://www.tenable.com/indicators/ioe/ad/C-GPOLICY-DISABLED-UNLINKED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[影响数据的危险应用程序权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-DATA</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-DATA</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>影响数据的危险应用程序权限</p>

      <h3>描述</h3>
      <p>Microsoft 在 Entra ID 中公开 API，以允许第三方应用程序以自己的名义对 Microsoft 服务执行操作（这被称为“应用程序权限”）。某些权限可能对这些服务存储的用户数据构成威胁。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-DATA">https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-DATA</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[具有可利用规则的动态组]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DYNAMIC-GROUP-FEATURING-AN-EXPLOITABLE-RULE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DYNAMIC-GROUP-FEATURING-AN-EXPLOITABLE-RULE</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>具有可利用规则的动态组</p>

      <h3>描述</h3>
      <p>攻击者可以通过操纵可自行修改的属性来利用 Microsoft Entra ID 中的动态组，将自己添加为组成员。这种操纵使得攻击者能够提升特权，并在未经授权的情况下访问与组相关的敏感资源。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DYNAMIC-GROUP-FEATURING-AN-EXPLOITABLE-RULE">https://www.tenable.com/indicators/ioe/entra/DYNAMIC-GROUP-FEATURING-AN-EXPLOITABLE-RULE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[空组]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/EMPTY-GROUP-MEID</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/EMPTY-GROUP-MEID</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>空组</p>

      <h3>描述</h3>
      <p>空组可能会导致混淆、影响安全性，并造成资源闲置。通常建议为组建立明确的目标，并确保组中包含相关成员。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/EMPTY-GROUP-MEID">https://www.tenable.com/indicators/ioe/entra/EMPTY-GROUP-MEID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[联合域列表]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>联合域列表</p>

      <h3>描述</h3>
      <p>恶意联合域配置是一种常见威胁，攻击者将其用作进入 Entra ID 租户的身份验证后门程序。验证现有和新添加的联合域对于确保其配置可靠且合法至关重要。此风险暴露指标提供了联合域及其相关属性的完整列表，有助于您对其安全状态做出明智决定。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST">https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已知的联合域后门程序]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</guid>
            <description><![CDATA[
      <p>Critical 严重性</p>

      <h3>名称</h3>
      <p>已知的联合域后门程序</p>

      <h3>描述</h3>
      <p>Microsoft Entra ID 允许通过联合功能将身份验证委派给其他提供者。然而，有更高特权的攻击者可以通过添加恶意联合域来利用该功能，从而实现持久性和特权提升。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR">https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已强制实施密码过期策略]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>已强制实施密码过期策略</p>

      <h3>描述</h3>
      <p>在 Microsoft Entra ID 域中强制实施密码过期策略可能会削弱安全性，因为它会频繁提示用户更改密码，而这往往导致用户使用弱密码、可预测的密码或重复使用的密码，从而降低帐户整体防护水平。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED">https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权帐户命名约定]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>特权帐户命名约定</p>

      <h3>描述</h3>
      <p>Entra ID 中特权用户的命名约定对于安全性、规范性、审计合规性至关重要，并且有助于管理。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[与 AD（混合帐户）同步的特权 Entra 帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>与 AD（混合帐户）同步的特权 Entra 帐户</p>

      <h3>描述</h3>
      <p>在 Entra ID 中具有特权角色的混合帐户（即从 Active Directory 同步）会构成安全风险，因为这类帐户允许入侵 AD 的攻击者转而入侵 Entra ID。Entra ID 中的特权帐户必须为纯云帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[应用程序的无限制用户同意]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>应用程序的无限制用户同意</p>

      <h3>描述</h3>
      <p>用户可以凭借 Entra ID 主动同意外部应用程序访问组织的数据，此类数据可能会被攻击者利用来进行“非法同意授予”攻击。将访问限制于经验证的发布者或要求管理员批准，便可以防止这种情况发生。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS">https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未经验证的域]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>未经验证的域</p>

      <h3>描述</h3>
      <p>您必须确认 Entra ID 中所有自定义域的所有权。仅暂时保留未经验证的域 - 您应该验证或移除此类域，以保持域列表的整洁，并促进高效的审核。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN">https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[影响数据的危险委派权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-DATA</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-DATA</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>影响数据的危险委派权限</p>

      <h3>描述</h3>
      <p>Microsoft 在 Entra ID 中公开 API，以允许第三方应用程序代表用户对 Microsoft 服务执行操作（这被称为“委派权限”）。某些权限可能对这些服务存储的用户数据构成威胁。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-DATA">https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-DATA</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Entra 安全默认设置未启用]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/ENTRA-SECURITY-DEFAULTS-NOT-ENABLED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/ENTRA-SECURITY-DEFAULTS-NOT-ENABLED</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>Entra 安全默认设置未启用</p>

      <h3>描述</h3>
      <p>Entra ID 安全默认设置提供预配置、Microsoft 建议的设置，以增强租户保护。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/ENTRA-SECURITY-DEFAULTS-NOT-ENABLED">https://www.tenable.com/indicators/ioe/entra/ENTRA-SECURITY-DEFAULTS-NOT-ENABLED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[来宾帐户与普通帐户具有相同的访问权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>来宾帐户与普通帐户具有相同的访问权限</p>

      <h3>描述</h3>
      <p>不建议将 Entra ID 配置为将来宾视为普通用户，因为这可能会使恶意的来宾对租户的资源进行全面侦查。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS">https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MFA 注册不要求使用托管设备]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>MFA 注册不要求使用托管设备</p>

      <h3>描述</h3>
      <p>要求使用托管设备进行 MFA 注册，可以在凭据被盗的情况下提高安全性，因为攻击者若无法访问托管设备，便难以完成恶意 MFA 注册。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION">https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[有风险的登录未要求进行 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>有风险的登录未要求进行 MFA</p>

      <h3>描述</h3>
      <p>MFA 为帐户提供强大保护，防止出现弱密码或泄露密码。根据安全最佳实践和标准，我们建议您对存在风险的登录要求进行 MFA，例如怀疑身份验证请求并非来自合法的身份拥有者时。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS">https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[非特权帐户缺少 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>非特权帐户缺少 MFA</p>

      <h3>描述</h3>
      <p>MFA 为帐户提供强大保护，防止出现弱密码或泄露密码。根据安全最佳实践和标准，我们建议您启用 MFA，即使针对非特权帐户。没有注册 MFA 方法的帐户无法从中获益。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT">https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[从未使用的特权用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>从未使用的特权用户</p>

      <h3>描述</h3>
      <p>从未使用的特权用户帐户容易遭到入侵，因为它们通常能够逃避防御措施的检测。此外，帐户可能配置了默认密码，使其成为攻击者的主要目标。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可访问 M365 服务的特权 Entra 帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>可访问 M365 服务的特权 Entra 帐户</p>

      <h3>描述</h3>
      <p>您应该为管理任务设置单独的 Entra 帐户：一个用于日常使用的标准帐户，以及另一个仅限于管理活动的特权帐户。此方法可减少特权帐户的攻击面。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[无强制措施的风险用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>无强制措施的风险用户</p>

      <h3>描述</h3>
      <p>阻止有风险的用户，以防止未经授权的访问和潜在漏洞。安全性最佳实践建议使用条件访问策略来阻止易受攻击的帐户进行 Entra ID 身份验证。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT">https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[不受限来宾帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>不受限来宾帐户</p>

      <h3>描述</h3>
      <p>默认情况下，系统授予 Entra ID 中的来宾用户有限的访问权限，以降低其在租户中的可见性；同时，您也可以通过进一步收紧这些限制来增强安全性和隐私性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS">https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[异常联合签名证书有效期]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>异常联合签名证书有效期</p>

      <h3>描述</h3>
      <p>如果联合签名证书的有效期异常长，则需要警惕，因为这可能表明攻击者在 Entra ID 中获得了更高的特权，并通过联合信任机制创建了后门程序。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD">https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[标准帐户注册应用程序的能力]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/ABILITY-OF-STANDARD-ACCOUNTS-TO-REGISTER-APPLICATIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/ABILITY-OF-STANDARD-ACCOUNTS-TO-REGISTER-APPLICATIONS</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>标准帐户注册应用程序的能力</p>

      <h3>描述</h3>
      <p>默认情况下，任何 Entra 用户都可以在租户中注册应用程序。虽然此功能很方便，并且不会立即导致安全漏洞，但它确实存在一定的风险。因此，根据最佳实践，Tenable 建议禁用此功能。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/ABILITY-OF-STANDARD-ACCOUNTS-TO-REGISTER-APPLICATIONS">https://www.tenable.com/indicators/ioe/entra/ABILITY-OF-STANDARD-ACCOUNTS-TO-REGISTER-APPLICATIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[允许多租户身份验证的应用程序]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/APPLICATION-ALLOWING-MULTI-TENANT-AUTHENTICATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/APPLICATION-ALLOWING-MULTI-TENANT-AUTHENTICATION</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>允许多租户身份验证的应用程序</p>

      <h3>描述</h3>
      <p>Entra 应用程序支持多租户身份验证，但如果在未完全理解其影响的情况下启用了这一配置，并且应用程序代码中没有实施适当的授权检查，则可能会导致恶意用户获得未经授权的访问权限。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/APPLICATION-ALLOWING-MULTI-TENANT-AUTHENTICATION">https://www.tenable.com/indicators/ioe/entra/APPLICATION-ALLOWING-MULTI-TENANT-AUTHENTICATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[条件访问策略禁用连续访问评估]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/CONDITIONAL-ACCESS-POLICY-DISABLES-CONTINUOUS-ACCESS-EVALUATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/CONDITIONAL-ACCESS-POLICY-DISABLES-CONTINUOUS-ACCESS-EVALUATION</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>条件访问策略禁用连续访问评估</p>

      <h3>描述</h3>
      <p>持续访问评估是 Entra ID 的一项安全功能，可对安全策略更改或用户状态更新做出快速反应。出于此原因，请勿禁用该功能。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/CONDITIONAL-ACCESS-POLICY-DISABLES-CONTINUOUS-ACCESS-EVALUATION">https://www.tenable.com/indicators/ioe/entra/CONDITIONAL-ACCESS-POLICY-DISABLES-CONTINUOUS-ACCESS-EVALUATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[本地环境未启用密码保护]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>本地环境未启用密码保护</p>

      <h3>描述</h3>
      <p>Microsoft Entra 密码保护是一项安全功能，可防止用户设置容易被猜中的密码，以增强组织的整体密码安全性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS">https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[公共 M365 组]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>公共 M365 组</p>

      <h3>描述</h3>
      <p>存储在 Entra ID 中的 Microsoft 365 组可以是公共组，也可以是私有组。公共组会带来安全风险，因为租户中的任何用户都可以加入这些组并访问其数据（Teams 聊天/文件、电子邮件等）。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP">https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[在 Microsoft Authenticator 通知中显示额外上下文]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>在 Microsoft Authenticator 通知中显示额外上下文</p>

      <h3>描述</h3>
      <p>为了提高可见性，请启用 Microsoft Authenticator 通知以显示额外的上下文，例如应用程序名称和地理位置。这有助于用户识别并拒绝潜在的恶意 MFA 或无密码身份验证请求，从而有效缓解 MFA 疲劳攻击的风险。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS">https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可疑的 AD 同步角色分配]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>可疑的 AD 同步角色分配</p>

      <h3>描述</h3>
      <p>Microsoft 针对 Active Directory 同步设计了两个隐藏的内置 Entra ID 角色，专门用于 Entra Connect 或 Cloud Sync 服务帐户。这些角色具有隐式特权，恶意攻击者可借此发起隐蔽攻击。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT">https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[休眠设备]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DORMANT-DEVICE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DORMANT-DEVICE</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>休眠设备</p>

      <h3>描述</h3>
      <p>休眠设备会带来安全风险，如过时的配置和未修补的漏洞。如果不定期监控和更新，这些过时设备可能会成为潜在的利用目标，从而破坏租户的完整性和数据机密性。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DORMANT-DEVICE">https://www.tenable.com/indicators/ioe/entra/DORMANT-DEVICE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[联合签名证书不匹配]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>联合签名证书不匹配</p>

      <h3>描述</h3>
      <p>Microsoft Entra ID 允许通过联合功能将身份验证委派给其他提供者。然而，有更高特权的攻击者可以通过添加恶意的令牌签名证书来利用该功能，从而实现持久性访问和特权提升。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH">https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[具有凭据的第一方服务主体]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>具有凭据的第一方服务主体</p>

      <h3>描述</h3>
      <p>第一方服务主体拥有强大的权限，然而因为他们处于隐藏状态、数量众多，而且为 Microsoft 所有，所以会被忽略。攻击者会向这些主体添加凭据，以隐蔽的方式利用主体的特权来提升特权和获得持久性特权，从而获益。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS">https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未阻止旧版身份验证]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>未阻止旧版身份验证</p>

      <h3>描述</h3>
      <p>旧版身份验证方法不支持多因素身份验证 (MFA)，这使得攻击者可以继续进行暴力破解、凭据填充和密码喷洒攻击。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED">https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[无需进行身份验证的托管设备]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>无需进行身份验证的托管设备</p>

      <h3>描述</h3>
      <p>要求托管设备防止未经授权的访问和潜在漏洞。安全性最佳实践建议使用条件访问策略来阻止利用非托管设备进行 Entra ID 身份验证。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION">https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[从未使用的设备]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>从未使用的设备</p>

      <h3>描述</h3>
      <p>您应避免预先创建从未使用的设备帐户，因为这种做法反映了安全管理上的不足，并可能带来安全风险。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[单成员组]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>单成员组</p>

      <h3>描述</h3>
      <p>不建议创建只有一个成员的组，因为这会增加冗余和复杂性。这种做法会增加层级结构从而不必要地增加管理复杂性，同时降低使用组来简化访问控制和管理的预期效率。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID">https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已启用临时访问通行证功能]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>已启用临时访问通行证功能</p>

      <h3>描述</h3>
      <p>临时访问通行证 (TAP) 功能是一种临时的身份验证方法，使用有时限或限制使用的通行码。虽然这是合法功能，但如果您的组织不需要，禁用此功能以减少攻击面会更安全。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED">https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权角色未要求进行 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>特权角色未要求进行 MFA</p>

      <h3>描述</h3>
      <p>MFA 为帐户提供强大保护，防止出现弱密码或泄露密码。根据安全最佳实践和标准，我们建议您启用 MFA，尤其是对于分配了特权角色的特权帐户。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE">https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未配置应用程序的管理员同意工作流]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/ADMIN-CONSENT-WORKFLOW-FOR-APPLICATIONS-NOT-CONFIGURED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/ADMIN-CONSENT-WORKFLOW-FOR-APPLICATIONS-NOT-CONFIGURED</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>未配置应用程序的管理员同意工作流</p>

      <h3>描述</h3>
      <p>Entra ID 中的管理员同意工作流允许非管理员用户通过一个结构化的审批流程来请求应用程序权限。如果未配置该工作流，尝试访问应用程序的用户可能会遇到错误，且无法请求同意。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/ADMIN-CONSENT-WORKFLOW-FOR-APPLICATIONS-NOT-CONFIGURED">https://www.tenable.com/indicators/ioe/entra/ADMIN-CONSENT-WORKFLOW-FOR-APPLICATIONS-NOT-CONFIGURED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[身份验证方法迁移未完成]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/AUTHENTICATION-METHODS-MIGRATION-NOT-COMPLETE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/AUTHENTICATION-METHODS-MIGRATION-NOT-COMPLETE</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>身份验证方法迁移未完成</p>

      <h3>描述</h3>
      <p>迁移到“身份验证方法”策略可简化并提升 Microsoft Entra ID 中的身份验证管理。此转换可简化管理，增强安全性，并提供对最新身份验证方法的支持。为避免因弃用旧策略造成中断，请在 2025 年 9 月之前完成迁移。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/AUTHENTICATION-METHODS-MIGRATION-NOT-COMPLETE">https://www.tenable.com/indicators/ioe/entra/AUTHENTICATION-METHODS-MIGRATION-NOT-COMPLETE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[影响租户的危险应用程序权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-THE-TENANT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-THE-TENANT</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>影响租户的危险应用程序权限</p>

      <h3>描述</h3>
      <p>Microsoft 在 Entra ID 中公开 API，以允许第三方应用程序以自己的名义对 Microsoft 服务执行操作（这被称为“应用程序权限”）。某些权限可能对整个 Microsoft Entra 租户造成严重威胁。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-THE-TENANT">https://www.tenable.com/indicators/ioe/entra/DANGEROUS-APPLICATION-PERMISSIONS-AFFECTING-THE-TENANT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[影响租户的危险委派权限]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-THE-TENANT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-THE-TENANT</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>影响租户的危险委派权限</p>

      <h3>描述</h3>
      <p>Microsoft 在 Entra ID 中公开 API，以允许第三方应用程序代表用户对 Microsoft 服务执行操作（这被称为“委派权限”）。某些权限可能对整个 Microsoft Entra 租户造成严重威胁。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-THE-TENANT">https://www.tenable.com/indicators/ioe/entra/DANGEROUS-DELEGATED-PERMISSIONS-AFFECTING-THE-TENANT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已禁用分配给特权角色的帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DISABLED-ACCOUNT-ASSIGNED-TO-PRIVILEGED-ROLE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DISABLED-ACCOUNT-ASSIGNED-TO-PRIVILEGED-ROLE</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>已禁用分配给特权角色的帐户</p>

      <h3>描述</h3>
      <p>如要拥有一个健全的帐户管理流程，则需要监视对特权角色的分配。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DISABLED-ACCOUNT-ASSIGNED-TO-PRIVILEGED-ROLE">https://www.tenable.com/indicators/ioe/entra/DISABLED-ACCOUNT-ASSIGNED-TO-PRIVILEGED-ROLE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[休眠的非特权用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DORMANT-NON-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DORMANT-NON-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>休眠的非特权用户</p>

      <h3>描述</h3>
      <p>休眠的非特权用户会带来安全风险，因为攻击者可以利用这些用户进行未经授权的访问。如果没有定期监控和停用，这些过期用户会通过扩大攻击面，为恶意活动创建潜在的入口点。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DORMANT-NON-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/DORMANT-NON-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[休眠的特权用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/DORMANT-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/DORMANT-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>Medium 严重性</p>

      <h3>名称</h3>
      <p>休眠的特权用户</p>

      <h3>描述</h3>
      <p>休眠的特权用户会带来安全风险，因为攻击者可以利用这些用户进行未经授权的访问。如果没有定期监控和停用，这些过期用户会通过扩大攻击面，为恶意活动创建潜在的入口点。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/DORMANT-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/DORMANT-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[具有特权角色的来宾帐户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>具有特权角色的来宾帐户</p>

      <h3>描述</h3>
      <p>来宾帐户是外部身份，当获得特权角色分配时，可能会造成安全风险。这将授予外部个体在您组织内的租户中相当大的特权。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE">https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特权帐户缺少 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>特权帐户缺少 MFA</p>

      <h3>描述</h3>
      <p>MFA 为帐户提供强大保护，防止出现弱密码或泄露密码。安全最佳实践和标准建议您启用 MFA，尤其是针对特权帐户。没有注册 MFA 方法的帐户无法从中获益。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT">https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[从未使用的非特权用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>从未使用的非特权用户</p>

      <h3>描述</h3>
      <p>从未使用的非特权用户帐户容易遭到入侵，因为它们通常能够逃避防御措施的检测。此外，帐户可能配置了默认密码，使其成为攻击者的主要目标。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[允许加入设备的用户]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</guid>
            <description><![CDATA[
      <p>Low 严重性</p>

      <h3>名称</h3>
      <p>允许加入设备的用户</p>

      <h3>描述</h3>
      <p>如果允许所有用户将不受限制的设备加入到 Entra 租户，这便危威胁制造者打开方便之门，使其可将恶意设备插入组织的身份系统中，并为其进行进一步入侵提供驻足点。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES">https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[管理员数量太多]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</guid>
            <description><![CDATA[
      <p>High 严重性</p>

      <h3>名称</h3>
      <p>管理员数量太多</p>

      <h3>描述</h3>
      <p>管理员拥有更高的特权，因此当管理员数量太多时，可能会增加攻击面，并因此造成安全风险。这也是最低特权原则未受到遵循的表现。</p>


      <p>了解详细信息  <a href="https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS">https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</a></p>
    ]]></description>
        </item>
    </channel>
</rss>