<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Indicators of Exposure</title>
        <link>https://www.tenable.com/indicators/feeds?type=ioe</link>
        <description>獲取最新的 Indicators of Exposure 更新</description>
        <lastBuildDate>Sat, 18 Apr 2026 09:30:52 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>指標</generator>
        <image>
            <title>Indicators of Exposure</title>
            <url>https://www.tenable.com/themes/custom/tenable/img/favicons/apple-touch-icon.png</url>
            <link>https://www.tenable.com/indicators/feeds?type=ioe</link>
        </image>
        <copyright>版權所有 2026 Tenable, Inc. 保留所有權利。</copyright>
        <atom:link href="https://www.tenable.com/indicators/feeds?type=ioe" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[動態物件錯誤設定和使用方式]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>動態物件錯誤設定和使用方式</p>

      <h3>說明</h3>
      <p>偵測動態物件及相關不安全設定。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS">https://www.tenable.com/indicators/ioe/ad/C-DYNAMIC-OBJECTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[BadSuccessor 危險的 dMSA 權限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>BadSuccessor 危險的 dMSA 權限</p>

      <h3>說明</h3>
      <p>BadSuccessor 是 Windows Server 2025 中的 Active Directory 特權提升缺陷，可利用 dMSA，讓攻擊者得以操控帳戶連結，甚至可能入侵網域。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR">https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[非必要群組]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>非必要群組</p>

      <h3>說明</h3>
      <p>確認沒有群組無成員或只有一名成員。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP">https://www.tenable.com/indicators/ioe/ad/C-UNNECESSARY-GROUP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[機密 Exchange 權限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>機密 Exchange 權限</p>

      <h3>說明</h3>
      <p>識別會影響 Exchange 資源或已指派給 Exchange 群組的潛在不安全權限。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-PERMISSIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[不支援或過時的 Exchange 伺服器]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>不支援或過時的 Exchange 伺服器</p>

      <h3>說明</h3>
      <p>偵測 Microsoft 不再支援的過時 Exchange 伺服器，以及缺少最新累積更新的 Exchange 伺服器。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-VERSION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Exchange 危險的錯誤設定]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>Exchange 危險的錯誤設定</p>

      <h3>說明</h3>
      <p>下文將列舉影響 Exchange 資源或其底層 Active Directory 結構描述物件的錯誤設定。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MISCONFIG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[混合 Entra ID 資訊]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>混合 Entra ID 資訊</p>

      <h3>說明</h3>
      <p>從內部部署 Active Directory 環境收集與 Microsoft Entra ID 同步的資源相關的資訊，例如混合使用者和電腦。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE">https://www.tenable.com/indicators/ioe/ad/C-AAD-INFORMATIVE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Exchange 群組成員]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>Exchange 群組成員</p>

      <h3>說明</h3>
      <p>敏感 Exchange 群組中的異常帳戶</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS">https://www.tenable.com/indicators/ioe/ad/C-EXCHANGE-MEMBERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[服務帳戶錯誤設定]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>服務帳戶錯誤設定</p>

      <h3>說明</h3>
      <p>顯示網域服務帳戶可能出現的錯誤設定。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT">https://www.tenable.com/indicators/ioe/ad/C-SERVICE-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Shadow Credentials]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>Shadow Credentials</p>

      <h3>說明</h3>
      <p>偵測「Windows Hello 企業版」功能及其相關金鑰憑證中的 Shadow Credentials 後門程式以及錯誤設定。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS">https://www.tenable.com/indicators/ioe/ad/C-SHADOW-CREDENTIALS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[受管理服務帳戶的危險錯誤設定]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>受管理服務帳戶的危險錯誤設定</p>

      <h3>說明</h3>
      <p>確定受管理服務帳戶 (MSAs) 已部署並正確設定。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE">https://www.tenable.com/indicators/ioe/ad/C-MSA-COMPLIANCE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WSUS 危險的錯誤設定]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>WSUS 危險的錯誤設定</p>

      <h3>說明</h3>
      <p>列出與 Windows Server 更新服務 (WSUS) 有關的錯誤設定參數。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING">https://www.tenable.com/indicators/ioe/ad/C-WSUS-HARDENING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[屬性集完整性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>屬性集完整性</p>

      <h3>說明</h3>
      <p>檢查屬性集的完整性並驗證權限</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY">https://www.tenable.com/indicators/ioe/ad/C-PROP-SET-SANITY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危險 SYSVOL 複製設定]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>危險 SYSVOL 複製設定</p>

      <h3>說明</h3>
      <p>檢查「分散式檔案系統複製」(DFS-R) 機制是否取代了「檔案複製服務」(FRS)。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG">https://www.tenable.com/indicators/ioe/ad/C-DFS-MISCONFIG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[密碼弱點偵測]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>密碼弱點偵測</p>

      <h3>說明</h3>
      <p>驗證可能會加劇 Active Directory 帳戶弱點的密碼弱點。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-HASHES-ANALYSIS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[針對勒索軟體的強化措施不足]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>針對勒索軟體的強化措施不足</p>

      <h3>說明</h3>
      <p>確認網域已建置強化措施，以防禦勒索軟體。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING">https://www.tenable.com/indicators/ioe/ad/C-RANSOMWARE-HARDENING</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[ADCS 危險設定錯誤]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>ADCS 危險設定錯誤</p>

      <h3>說明</h3>
      <p>列出與 Active Directory 憑證服務 (AD CS) 公開金鑰基礎架構 (PKI) 相關的危險權限和設定錯誤的參數。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS">https://www.tenable.com/indicators/ioe/ad/C-PKI-DANG-ACCESS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GPO 執行合理性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>GPO 執行合理性</p>

      <h3>說明</h3>
      <p>驗證套用至網域電腦的群組原則物件 (GPO) 是否合理。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY">https://www.tenable.com/indicators/ioe/ad/C-GPO-EXEC-SANITY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危險機密特權]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>危險機密特權</p>

      <h3>說明</h3>
      <p>識別設定不當的機密特權會降低目錄基礎架構的安全性。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES">https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-SENSITIVE-PRIVILEGES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[帳戶上的對應憑證]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>帳戶上的對應憑證</p>

      <h3>說明</h3>
      <p>確定沒有指派給物件的低強度憑證對應。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER">https://www.tenable.com/indicators/ioe/ad/C-SENSITIVE-CERTIFICATES-ON-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未使用受保護的使用者群組]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>未使用受保護的使用者群組</p>

      <h3>說明</h3>
      <p>驗證非受保護的使用者群組成員的特權使用者。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED">https://www.tenable.com/indicators/ioe/ad/C-PROTECTED-USERS-GROUP-UNUSED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可能有空白密碼的帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>可能有空白密碼的帳戶</p>

      <h3>說明</h3>
      <p>識別允許空白密碼的使用者帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-NOT-REQUIRED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[獲允許將電腦加入網域的使用者]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>獲允許將電腦加入網域的使用者</p>

      <h3>說明</h3>
      <p>確認一般使用者無法將外部電腦加入網域。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS">https://www.tenable.com/indicators/ioe/ad/C-USERS-CAN-JOIN-COMPUTERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[AD 結構描述中的危險權限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>AD 結構描述中的危險權限</p>

      <h3>說明</h3>
      <p>列出可能會遭到利用進行長期潛伏的異常結構描述實體。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA">https://www.tenable.com/indicators/ioe/ad/C-ABNORMAL-ENTRIES-IN-SCHEMA</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[使用舊密碼的使用者帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>使用舊密碼的使用者帳戶</p>

      <h3>說明</h3>
      <p>檢查 Active Directory 中所有的作用中帳戶密碼是否有定期更新，以降低憑證遭竊的風險。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-USER-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[驗證與 Microsoft Entra Connect 帳戶相關的權限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>驗證與 Microsoft Entra Connect 帳戶相關的權限</p>

      <h3>說明</h3>
      <p>確保設定於 Microsoft Entra Connect 帳戶的權限合理</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT">https://www.tenable.com/indicators/ioe/ad/C-AAD-CONNECT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[不正當使用者管理的網域控制器]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>不正當使用者管理的網域控制器</p>

      <h3>說明</h3>
      <p>由於危險存取權限，部分網域控制器可由非系統管理使用者管理。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-DC-ACCESS-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[對使用者套用脆弱密碼原則]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>對使用者套用脆弱密碼原則</p>

      <h3>說明</h3>
      <p>部分套用於特定使用者帳戶的密碼原則不夠強大，可能會導致憑證遭竊。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY">https://www.tenable.com/indicators/ioe/ad/C-PASSWORD-POLICY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[驗證機密 GPO 物件和檔案權限]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>驗證機密 GPO 物件和檔案權限</p>

      <h3>說明</h3>
      <p>確認指派至連結機密容器 (例如網域控制器或 OU) 之 GPO 物件與檔案的權限正確且安全。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-GPO-SD-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[根物件權限允許類似 DCSync 的攻擊]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>根物件權限允許類似 DCSync 的攻擊</p>

      <h3>說明</h3>
      <p>檢查根物件是否具有可讓未授權使用者竊取驗證憑證的不安全權限。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-ROOTOBJECTS-SD-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[使用 Windows 2000 以前版本的相容存取控制的帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>使用 Windows 2000 以前版本的相容存取控制的帳戶</p>

      <h3>說明</h3>
      <p>檢查可繞過安全措施的「Windows 2000 以前版本相容存取」群組帳戶成員。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS">https://www.tenable.com/indicators/ioe/ad/C-PRE-WIN2000-ACCESS-MEMBERS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[具有危險 SID History 屬性的帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>具有危險 SID History 屬性的帳戶</p>

      <h3>說明</h3>
      <p>使用 SID history 屬性中的特權 SID 檢查使用者或電腦帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY">https://www.tenable.com/indicators/ioe/ad/C-ACCOUNTS-DANG-SID-HISTORY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[在 Active Directory PKI 中使用脆弱的密碼編譯演算法]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>在 Active Directory PKI 中使用脆弱的密碼編譯演算法</p>

      <h3>說明</h3>
      <p>針對部署在內部 Active Directory PKI 上的根憑證，識別其中所用的脆弱密碼編譯演算法。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO">https://www.tenable.com/indicators/ioe/ad/C-PKI-WEAK-CRYPTO</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[使用者主要群組]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>使用者主要群組</p>

      <h3>說明</h3>
      <p>驗證使用者的主要群組未經變更</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID">https://www.tenable.com/indicators/ioe/ad/C-DANG-PRIMGROUPID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危險的 Kerberos 委派]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>危險的 Kerberos 委派</p>

      <h3>說明</h3>
      <p>檢查未經授權的 Kerberos 委派，並確保針對特權使用者提供相關保護。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG">https://www.tenable.com/indicators/ioe/ad/C-UNCONST-DELEG</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可逆密碼]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>可逆密碼</p>

      <h3>說明</h3>
      <p>確認未啟用以可逆格式儲存密碼的選項。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS">https://www.tenable.com/indicators/ioe/ad/C-USERS-REVER-PWDS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GPO 中的可逆密碼]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>GPO 中的可逆密碼</p>

      <h3>說明</h3>
      <p>檢查 GPO 喜好設定是否不允許使用可逆格式的密碼。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO">https://www.tenable.com/indicators/ioe/ad/C-REVER-PWD-GPO</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[確保 SDProp 一致性]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>確保 SDProp 一致性</p>

      <h3>說明</h3>
      <p>將 AdminSDHolder 物件控制在初始狀態。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY">https://www.tenable.com/indicators/ioe/ad/C-SDPROP-CONSISTENCY</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[KRBTGT 帳戶的上次密碼變更]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>KRBTGT 帳戶的上次密碼變更</p>

      <h3>說明</h3>
      <p>檢查 KRBTGT 帳戶是否已超過建議的時間間隔未變更密碼。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD">https://www.tenable.com/indicators/ioe/ad/C-KRBTGT-PASSWORD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特權帳戶執行 Kerberos 服務]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>特權帳戶執行 Kerberos 服務</p>

      <h3>說明</h3>
      <p>偵測具有會影響安全性之服務主體名稱 (SPN) 屬性的高特權帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN">https://www.tenable.com/indicators/ioe/ad/C-PRIV-ACCOUNTS-SPN</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[休眠帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>休眠帳戶</p>

      <h3>說明</h3>
      <p>偵測可能會導致安全風險的未用休眠帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS">https://www.tenable.com/indicators/ioe/ad/C-SLEEPING-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[危險信任關係]]></title>
            <link>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</link>
            <guid>https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>危險信任關係</p>

      <h3>說明</h3>
      <p>識別設定錯誤的信任關係屬性，其會降低目錄基礎架構的安全性。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP">https://www.tenable.com/indicators/ioe/ad/C-DANGEROUS-TRUST-RELATIONSHIP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[同盟網域清單]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>同盟網域清單</p>

      <h3>說明</h3>
      <p>惡意同盟網域設定是攻擊者常用的威脅技術，用於在 Entra ID 租用戶中充當驗證後門程式。驗證現有和新增的同盟網域對於確保其設定正當可信至關重要。此曝險指標提供同盟網域及其相關屬性的完整清單，以協助您根據相關資訊有效判斷其安全狀態。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST">https://www.tenable.com/indicators/ioe/entra/FEDERATED-DOMAINS-LIST</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已知的同盟網域後門程式]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</guid>
            <description><![CDATA[
      <p>嚴重性: Critical</p>

      <h3>名稱</h3>
      <p>已知的同盟網域後門程式</p>

      <h3>說明</h3>
      <p>Microsoft Entra ID 可透過同盟的方式，將驗證工作委派給其他提供者。但是，獲得進階特權的攻擊者可以新增惡意同盟網域來利用此功能，進而達到潛伏和特權提升的目的。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR">https://www.tenable.com/indicators/ioe/entra/KNOWN-FEDERATED-DOMAIN-BACKDOOR</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已強制執行密碼過期]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>已強制執行密碼過期</p>

      <h3>說明</h3>
      <p>在 Microsoft Entra ID 網域中強制執行密碼過期可能會促使使用者頻繁地變更密碼，進而使用脆弱、可預測或重複的密碼，進而破壞安全性，降低整體帳戶的保護力。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED">https://www.tenable.com/indicators/ioe/entra/PASSWORD-EXPIRATION-ENFORCED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特權帳戶命名慣例]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>特權帳戶命名慣例</p>

      <h3>說明</h3>
      <p>Entra ID 中特權使用者的命名慣例對於強化安全性、促進標準化並提升稽核合規性至關重要，同時也使系統更便於管理。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ACCOUNT-NAMING-CONVENTION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[與 AD (混合帳戶) 同步的特權 Entra 帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>與 AD (混合帳戶) 同步的特權 Entra 帳戶</p>

      <h3>說明</h3>
      <p>在 Entra ID 中擁有特權角色的混合帳戶 (即從 Active Directory 同步) 會帶來安全性風險，因為入侵 AD 的攻擊者可利用此類帳戶轉而入侵 Entra ID。Entra ID 中的特權帳戶必須為雲端專用帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-SYNCHRONIZED-WITH-AD-HYBRID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[應用程式的非受限使用者同意]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>應用程式的非受限使用者同意</p>

      <h3>說明</h3>
      <p>Entra ID 允許使用者自動同意外部應用程式存取組織資料，攻擊者可能會在「非法同意授予」攻擊中利用這項漏洞。為了防止此問題，您可以僅授予存取權給經過驗證的發行者，或啟用管理員核准機制。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS">https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-USER-CONSENT-FOR-APPLICATIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未驗證的網域]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>未驗證的網域</p>

      <h3>說明</h3>
      <p>您必須在 Entra ID 中確認所有自訂網域的所有權。僅暫時保留未驗證的網域。請驗證網域或將其移除，讓網域清單保持條理並提升審查效率。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN">https://www.tenable.com/indicators/ioe/entra/UNVERIFIED-DOMAIN</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[訪客帳戶和一般帳戶享有同等存取權]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>訪客帳戶和一般帳戶享有同等存取權</p>

      <h3>說明</h3>
      <p>不建議在 Entra ID 的設定中將訪客視為一般使用者，因為這樣一來，惡意訪客就有機會對租用戶的資源進行全面偵察。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS">https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNTS-WITH-EQUAL-ACCESS-TO-NORMAL-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[進行 MFA 註冊時無需使用受管理裝置]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>進行 MFA 註冊時無需使用受管理裝置</p>

      <h3>說明</h3>
      <p>要求使用受管理裝置進行 MFA 註冊，能有效阻止攻擊者在憑證遭竊的情況下，註冊惡意 MFA，因為若攻擊者無法取得受管理裝置，也就無法完成註冊流程。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION">https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-MFA-REGISTRATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[風險性登入未要求使用 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>風險性登入未要求使用 MFA</p>

      <h3>說明</h3>
      <p>MFA 為帳戶提供強大保護，防止出現弱式密碼或易遭洩漏的密碼。根據安全性最佳做法和標準的建議，您應針對風險性登入啟用 MFA，例如當驗證請求可能並非來自合法身分所有者的情況下。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS">https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-RISKY-SIGN-INS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[非特權帳戶缺少 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>非特權帳戶缺少 MFA</p>

      <h3>說明</h3>
      <p>MFA 為帳戶提供強大保護，防止出現弱式密碼或易遭洩漏的密碼。建議的安全性最佳做法和標準是啟用 MFA，即使是非特權帳戶亦是如此。未註冊 MFA 方法的帳戶無法受到此機制保護。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT">https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-NON-PRIVILEGED-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[待啟用的特權使用者]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>待啟用的特權使用者</p>

      <h3>說明</h3>
      <p>待啟用的特權使用者帳戶很容易受到入侵，因為這些帳戶通常能避開防禦措施的偵測。此外，這類帳戶可能使用預設密碼，也使它們成為攻擊者的首要目標。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可存取 M365 服務的特權 Entra 帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>可存取 M365 服務的特權 Entra 帳戶</p>

      <h3>說明</h3>
      <p>系統管理工作應使用獨立 Entra 帳戶來執行: 請開設一個標準帳戶用於日常所需，另外再開一個特權帳戶專門用於管理活動。這種方法可減少特權帳戶的攻擊破綻。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES">https://www.tenable.com/indicators/ioe/entra/PRIVILEGED-ENTRA-ACCOUNT-WITH-ACCESS-TO-M365-SERVICES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未強制執行的風險使用者]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>未強制執行的風險使用者</p>

      <h3>說明</h3>
      <p>封鎖風險使用者，以防止未經授權的存取和潛在的缺口。安全性最佳做法建議使用條件式存取原則，以阻止易受攻擊的帳戶驗證 Entra ID。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT">https://www.tenable.com/indicators/ioe/entra/RISKY-USERS-WITHOUT-ENFORCEMENT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未受限訪客帳戶]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>未受限訪客帳戶</p>

      <h3>說明</h3>
      <p>根據預設，雖然 Entra ID 中的訪客使用者本就只能取得有限存取權，因此瀏覽權限比其他租用戶群體更低，但您也可以進一步強化這些限制以提升安全性和私密性。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS">https://www.tenable.com/indicators/ioe/entra/UNRESTRICTED-GUEST-ACCOUNTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[同盟簽署憑證的有效期出現異常]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>同盟簽署憑證的有效期出現異常</p>

      <h3>說明</h3>
      <p>同盟簽署憑證的有效期過長可能會引發疑慮，因為這表示攻擊者或許已在 Entra ID 中取得進階特權，並透過同盟信任機制建立後門程式。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD">https://www.tenable.com/indicators/ioe/entra/UNUSUAL-FEDERATION-SIGNING-CERTIFICATE-VALIDITY-PERIOD</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[內部部署環境未啟用密碼保護]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>內部部署環境未啟用密碼保護</p>

      <h3>說明</h3>
      <p>Microsoft Entra 密碼保護是一項安全功能，可防止使用者設定容易被猜中的密碼，以增強組織的整體密碼安全性。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS">https://www.tenable.com/indicators/ioe/entra/PASSWORD-PROTECTION-NOT-ENABLED-FOR-ON-PREMISES-ENVIRONMENTS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[公開 M365 群組]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>公開 M365 群組</p>

      <h3>說明</h3>
      <p>儲存在 Entra ID 中的 Microsoft 365 群組，其設定可能為公開或私人。公開群組會帶來安全性風險，因為租用戶中的任何使用者都可以加入並獲得其資料的存取權 (Teams 聊天記錄/檔案、電子郵件等)。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP">https://www.tenable.com/indicators/ioe/entra/PUBLIC-M365-GROUP</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[在 Microsoft 驗證器通知中顯示更多背景資訊]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>在 Microsoft 驗證器通知中顯示更多背景資訊</p>

      <h3>說明</h3>
      <p>為了讓資訊一目了然，請啟用 Microsoft Authenticator 通知以顯示更多背景資訊，例如應用程式名稱和地理位置。使用者可透過此功能判斷並阻止惡意的 MFA 或無密碼驗證請求，有效降低 MFA 疲勞攻擊的風險。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS">https://www.tenable.com/indicators/ioe/entra/SHOW-ADDITIONAL-CONTEXT-IN-MICROSOFT-AUTHENTICATOR-NOTIFICATIONS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[可疑的 AD 同步處理角色指派]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>可疑的 AD 同步處理角色指派</p>

      <h3>說明</h3>
      <p>Microsoft 針對 Active Directory 同步處理設計了兩個隱藏的內建 Entra ID 角色，專門供 Entra Connect 或 Cloud Sync 服務帳戶使用。這些角色具有隱含的特權，可能會遭到惡意攻擊者利用，藉此在難以察覺的情況下發動攻擊。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT">https://www.tenable.com/indicators/ioe/entra/SUSPICIOUS-DIRECTORY-SYNCHRONIZATION-ACCOUNTS-ROLE-ASSIGNMENT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[同盟簽署憑證不相符]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>同盟簽署憑證不相符</p>

      <h3>說明</h3>
      <p>Microsoft Entra ID 可透過同盟的方式，將驗證工作委派給其他提供者。但是，獲得進階特權的攻擊者可以新增權杖簽署憑證來利用此功能，進而達到潛伏和特權提升的目的。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH">https://www.tenable.com/indicators/ioe/entra/FEDERATION-SIGNING-CERTIFICATES-MISMATCH</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[擁有憑證的第一方服務主體]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>擁有憑證的第一方服務主體</p>

      <h3>說明</h3>
      <p>第一方服務主體擁有強大權限，然而因為他們處於隱藏狀態、數量眾多，且為 Microsoft 所有，因而會被忽略。攻擊者會將憑證新增至主體，在神不知鬼不覺的情況下利用主體特權達成特權提升和潛伏的目的。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS">https://www.tenable.com/indicators/ioe/entra/FIRST-PARTY-SERVICE-PRINCIPAL-WITH-CREDENTIALS</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未封鎖舊型驗證]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>未封鎖舊型驗證</p>

      <h3>說明</h3>
      <p>舊型驗證方法不支援多因素驗證 (MFA)，導致攻擊者能夠繼續執行暴力密碼破解、憑證填充和密碼噴濺攻擊。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED">https://www.tenable.com/indicators/ioe/entra/LEGACY-AUTHENTICATION-NOT-BLOCKED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[驗證時無需使用受管理裝置]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</guid>
            <description><![CDATA[
      <p>嚴重性: Medium</p>

      <h3>名稱</h3>
      <p>驗證時無需使用受管理裝置</p>

      <h3>說明</h3>
      <p>要求使用受管理裝置，以防止未經授權的存取和潛在的安全缺口。安全性最佳做法建議使用條件式存取原則，阻止未受管理裝置進行 Entra ID 驗證。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION">https://www.tenable.com/indicators/ioe/entra/MANAGED-DEVICES-NOT-REQUIRED-FOR-AUTHENTICATION</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[待啟用裝置]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>待啟用裝置</p>

      <h3>說明</h3>
      <p>您應避免使用預先建立的待啟用裝置帳戶，因為這反映了不良的操作習慣，並且可能帶來安全風險。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-DEVICE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[單一成員群組]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>單一成員群組</p>

      <h3>說明</h3>
      <p>我們不建議建立只有一個成員的群組，因為這會造成系統冗餘及複雜化。這種做法會增加層級，徒增管理難度，並背離使用群組來簡化存取權控制和管理模式的初衷。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID">https://www.tenable.com/indicators/ioe/entra/SINGLE-MEMBER-GROUP-MEID</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[已啟用臨時存取密碼功能]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>已啟用臨時存取密碼功能</p>

      <h3>說明</h3>
      <p>臨時存取密碼 (TAP) 功能是一種臨時驗證方法，使用有時間或使用限制的密碼。雖然這是正當的功能，但在貴組織不需要的情況下，建議您將其停用以減少攻擊破綻。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED">https://www.tenable.com/indicators/ioe/entra/TEMPORARY-ACCESS-PASS-FEATURE-ENABLED</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[未針對特權角色要求使用 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>未針對特權角色要求使用 MFA</p>

      <h3>說明</h3>
      <p>MFA 為帳戶提供強大保護，防止出現弱式密碼或易遭洩漏的密碼。建議的安全性最佳做法和標準是啟用 MFA，特別是具有特權角色的特權帳戶。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE">https://www.tenable.com/indicators/ioe/entra/MFA-NOT-REQUIRED-FOR-A-PRIVILEGED-ROLE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[訪客帳戶具有特權角色]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>訪客帳戶具有特權角色</p>

      <h3>說明</h3>
      <p>訪客帳戶是外部身分，一旦獲派特權角色就可能造成安全風險。這會將租用戶的重大特權授予組織外部人員。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE">https://www.tenable.com/indicators/ioe/entra/GUEST-ACCOUNT-WITH-A-PRIVILEGED-ROLE</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[特權帳戶缺少 MFA]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>特權帳戶缺少 MFA</p>

      <h3>說明</h3>
      <p>MFA 為帳戶提供強大保護，防止出現弱式密碼或易遭洩漏的密碼。建議的安全性最佳做法和標準是啟用 MFA，尤其是針對特權帳戶。未註冊 MFA 方法的帳戶無法受到此機制保護。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT">https://www.tenable.com/indicators/ioe/entra/MISSING-MFA-FOR-PRIVILEGED-ACCOUNT</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[待啟用的非特權使用者]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>待啟用的非特權使用者</p>

      <h3>說明</h3>
      <p>待啟用的非特權使用者帳戶很容易受到入侵，因為這些帳戶通常能避開防禦措施的偵測。此外，這類帳戶可能使用預設密碼，也使它們成為攻擊者的首要目標。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER">https://www.tenable.com/indicators/ioe/entra/NEVER-USED-NON-PRIVILEGED-USER</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[獲允許加入裝置的使用者]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</guid>
            <description><![CDATA[
      <p>嚴重性: Low</p>

      <h3>名稱</h3>
      <p>獲允許加入裝置的使用者</p>

      <h3>說明</h3>
      <p>若允許所有使用者將不受限制的裝置加入 Entra 租用戶，就是為威脅執行者打開了方便的大門，使其能順利地將惡意裝置植入組織的身分系統，並為其進一步的入侵提供立足點。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES">https://www.tenable.com/indicators/ioe/entra/USERS-ALLOWED-TO-JOIN-DEVICES</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[管理員數量過多]]></title>
            <link>https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</link>
            <guid>https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</guid>
            <description><![CDATA[
      <p>嚴重性: High</p>

      <h3>名稱</h3>
      <p>管理員數量過多</p>

      <h3>說明</h3>
      <p>管理員擁有進階特權，因此當管理員數量過多時，可能會增加攻擊破綻，造成安全性風險。這也是未遵循最低特權原則的跡象。</p>


      <p>閱讀更多:  <a href="https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS">https://www.tenable.com/indicators/ioe/entra/HIGH-NUMBER-OF-ADMINISTRATORS</a></p>
    ]]></description>
        </item>
    </channel>
</rss>