AD Pro Toolkit > Docs > Reports
Active Directory Reports
AD Pro Toolkit includes built-in Active Directory reports across 11 categories. Run one in a couple of clicks, export to CSV, Excel or PDF, and schedule it to run automatically.
How to run a report
- Click Reports and open a category in the sidebar, for example Users.
- Select a report and click Run.
Any report can be exported to CSV, Excel or PDF, and scheduled to run and email itself on a recurring basis. Most reports also let you pick an OU, choose columns, and filter the results in place.
Users
| Report | Description |
|---|---|
| All Users | All user accounts in Active Directory |
| Count of Users in Each OU | User count breakdown by organizational unit |
| Dial-in Allowed | Users with dial-in access enabled |
| Dial-in Not Allowed | Users with dial-in access denied |
| Recently Created Users | Users created in the last 30 days |
| Recently Deleted Users | Users deleted from Active Directory |
| Recently Modified Users | Users modified in the last 30 days |
| Users by Department | User accounts grouped by department |
| Users SID | Users and their security identifiers (SIDs) |
| Users with Home Folder | Users that have a home folder configured |
| Users with Logon Script | Users that have a logon script assigned |
| Users with Manager | Users that have a manager assigned in AD |
| Users with Photo | Users that have a photo configured in AD |
| Users with Profile Path | Users that have a profile path configured |
| Users without Home Folder | Users that do not have a home folder configured |
| Users without Logon Script | Users that do not have a logon script assigned |
| Users without Manager | Users that do not have a manager assigned in AD |
| Users without Photo | Users that do not have a photo configured in AD |
| Users without Profile Path | Users that do not have a profile path configured |
User Status
| Report | Description |
|---|---|
| Disabled Users | All disabled user accounts in Active Directory |
| Enabled Users | All enabled user accounts in Active Directory |
| Expired User Accounts | Users whose accounts have expired |
| Users Hidden from Address List | User accounts hidden from the Exchange Global Address List |
| Inactive Users | Users who have not logged on in 90 days or more |
| Locked Out Users | Users currently locked out of their accounts |
| Soon to Expire User Accounts | Users whose accounts will expire within 30 days |
| UAC Flags | Users and their UAC flag values |
| Users Not Protected from Deletion | Users not protected from accidental deletion |
| Users Protected from Deletion | Users protected from accidental deletion |
User Password Reports
| Report | Description |
|---|---|
| Bad Password Attempt Details | Failed login attempts per user per domain controller |
| Change Password at Next Logon | Users required to change password at next logon |
| Password Expired Users | Users whose passwords have expired |
| Password Last Set Date | Users and the date their password was last set |
| Password Not Required | Users with the password not required flag enabled |
| Password Set to Never Expire | Users with the password never expires flag enabled |
| Recent Password Changes | Users who changed their password in the last 30 days |
| Reversible Password Encryption Enabled | Users with reversible password encryption enabled |
| Soon to Expire Passwords | Users whose passwords will expire within 14 days |
| User Password Details | Detailed password status for all users |
| Users Can’t Change Password | Users who cannot change their own password |
| Users with Old Password | Users who have not changed their password in 90 days or more |
| Users with Password Expiry | Users whose passwords have an expiry date set |
Logon Reports
| Report | Description |
|---|---|
| Logon Workstation Restrictions | Users with workstation logon restrictions configured |
| Never Logged On Users | Users who have never logged on to the domain |
| Recently Logged On Users | Users who have logged on in the last 30 days |
| True Last Logon Time | Accurate last logon time collected across all domain controllers |
| User Logon Hours | Users with logon hour restrictions configured |
Computers
| Report | Description |
|---|---|
| All Computers | All computer accounts in Active Directory |
| BitLocker Enabled | Computers with BitLocker recovery keys stored in Active Directory |
| BitLocker Not Enabled | Computers without BitLocker recovery keys in Active Directory |
| Computers by OS | Computer accounts grouped by operating system version |
| Disabled Computers | Computer accounts that are currently disabled in Active Directory |
| Domain Controllers | All domain controller computer accounts |
| Enabled Computers | Computer accounts that are currently enabled in Active Directory |
| Inactive Computers | Computers that have not logged on recently, so potential stale accounts |
| LAPS Enabled | Computers with LAPS (Local Administrator Password Solution) enabled |
| LAPS Not Enabled | Computers without LAPS, a potential security gap |
| LAPS Passwords | View LAPS passwords for computers (requires read permission on the LAPS attributes) |
| Managed Computers | Computers with a Managed By value set in Active Directory |
| Never Logged On Computers | Computers that have never logged on to the domain |
| True Last Logon Computers | Accurate last logon time for computers, collected across all domain controllers |
| Not Protected from Deletion | Computers not protected from accidental deletion in Active Directory |
| Protected from Deletion | Computers protected from accidental deletion in Active Directory |
| Recently Created Computers | Computers created in the last 30 days |
| Recently Deleted Computers | Computers deleted from Active Directory, from the Deleted Objects container |
| Recently Modified Computers | Computers modified in the last 30 days |
| Servers | All server computer accounts in Active Directory |
| Trusted for Delegation | Computers with the TRUSTED_FOR_DELEGATION flag set (unconstrained delegation) |
| Unmanaged Computers | Computers without a Managed By value in Active Directory |
| Workstations | All workstation computer accounts in Active Directory |
Groups
| Report | Description |
|---|---|
| All Groups | All groups in Active Directory |
| Default Groups | Default groups from the CN=Builtin and CN=Users containers |
| Distribution Groups | All distribution groups in Active Directory |
| Empty Groups | Groups with no members |
| Managed Groups | Groups that have a manager assigned |
| Groups Not Protected from Deletion | Groups not protected from accidental deletion |
| Groups Protected from Deletion | Groups protected from accidental deletion |
| Recently Created Groups | Groups created in the last 30 days |
| Recently Deleted Groups | Groups deleted from Active Directory, from the Deleted Objects container |
| Recently Modified Groups | Groups modified in the last 30 days |
| Security Groups | All security groups in Active Directory |
| Unmanaged Groups | Groups without a manager assigned |
Group Membership
| Report | Description |
|---|---|
| Empty Groups | Groups with no members |
| Group Members | All groups and their members |
| Group Member Summary | Groups with all members listed in a single row |
| Groups with Disabled User Members | Groups containing disabled user accounts |
| Groups with Nested Groups | Groups that have other groups as members |
| Large Groups | Groups sorted by member count, largest first |
| Nested Group Membership | All groups and their nested members |
| Privileged Group Members | Members of privileged administrative groups |
| User Group Membership | Users and the groups they belong to |
| User Membership Summary | Users and their group membership count |
| Users Not in Group | Select a group to find users who are not members of it |
| Users Primary Group | All users and their primary group |
| Users with No Groups | Users that are not a member of any group |
Security
| Report | Description |
|---|---|
| AD ACL Scanner | Audit permissions (ACLs) on Active Directory objects |
| AdminCount Orphans | Objects with adminCount=1 that are no longer members of any privileged group |
| Find Service Accounts | Scans remote computers for scheduled tasks and services running under domain accounts |
| Fine-Grained Password Policies | Password Settings Objects (PSOs) that define granular password policies for specific users or groups |
| Kerberoastable Accounts | User accounts with Service Principal Names (SPNs) set, which are vulnerable to Kerberoasting attacks |
| Local Certificates Report | Scans remote computers for locally installed certificates |
| Managed Service Accounts | Managed Service Accounts (MSA) and Group Managed Service Accounts (gMSA) in Active Directory |
| NTFS Permissions Report | Lists users and groups, folder access and permissions |
| Privileged Non-Expiring Passwords | Members of privileged groups whose passwords are set to never expire |
| Stale Privileged Accounts | Privileged group members that have not logged in within the selected time period |
| Unconstrained Delegation | User and computer accounts configured for unconstrained, constrained, or resource-based constrained delegation |
| Potential Service Accounts | User accounts that may be service accounts, based on naming, attributes and configuration |
| Users with SID History | User accounts that have SID History entries, which may indicate migration artifacts or privilege risks |
Domain-wide checks such as the krbtgt password age, tombstone lifetime, forest functional level, duplicate SPNs and Protected Users are not separate reports. They run as checks inside AD Security Assessment, on the Security tab.
Group Policy
| Report | Description |
|---|---|
| All GPOs | All Group Policy Objects (GPOs) in the domain |
| Blocked Inheritance | Organizational Units with GPO inheritance blocked, so parent GPOs will not apply to them |
| Disabled GPO Links | GPO links that exist but are disabled, so the GPO will not apply at those locations |
| Duplicate/Conflicting GPOs | Settings configured in multiple GPOs, highlighting conflicts where the values differ |
| Empty GPOs | Group Policy Objects with no configured settings, detected via GPMC |
| Enforced GPOs | Group Policy Objects with enforcement enabled on one or more link locations |
| GPO Link Order | GPO link precedence per OU. A lower order number means higher priority, applied last and winning conflicts |
| GPO Permissions | Security permissions on each Group Policy Object: who can read, edit and delete GPOs |
| GPO Scripts | Logon, Logoff, Startup and Shutdown scripts configured in Group Policy Objects |
| Recently Modified GPOs | Group Policy Objects modified within a selected time period |
| Unused GPOs | Group Policy Objects that are not linked to any OU, site or domain |
Organizational Units
| Report | Description |
|---|---|
| All OUs | All Organizational Units in the domain |
| Deleted OUs | Organizational Units deleted from Active Directory, from the Deleted Objects container |
| Empty OUs | Organizational Units with no objects directly contained |
| Managed OUs | Organizational Units with a Managed By value configured |
| OUs Not Protected from Deletion | Organizational Units not protected from accidental deletion |
| OUs Protected from Deletion | Organizational Units protected from accidental deletion |
| OUs with Delegation | Organizational Units that have non-default delegated permissions applied |
| OUs with Linked GPOs | Organizational Units that have Group Policy Objects linked to them |
| OUs with Object Count | Number of objects directly contained in each Organizational Unit |
| Recently Created OUs | Organizational Units created within a selected time period |
| Recently Modified OUs | Organizational Units modified within a selected time period |
| Unmanaged OUs | Organizational Units with no Managed By value configured |
Contacts
| Report | Description |
|---|---|
| All Contacts | All contact objects in Active Directory |
| Recently Created Contacts | Contact objects created in the last 30 days |
| Recently Modified Contacts | Contact objects modified in the last 30 days |
| Managed Contacts | Contact objects that have a manager assigned |
| Unmanaged Contacts | Contact objects without a manager assigned |
| Contacts without Mail | Contact objects that do not have an email address |
Active Directory Pro · AD Pro Toolkit docs · Download · Pricing