How to run a report
Any report can be exported to CSV, Excel or PDF, and scheduled to run and email itself on a recurring basis. Most reports also let you pick an OU, choose columns, and filter the results in place.
- Click Reports and open a category in the sidebar, for example Users.
- Select a report and click Run.
Users
| Report | Description |
|---|---|
| All Users | All user accounts in Active Directory |
| Count of Users in Each OU | User count breakdown by organizational unit |
| Dial-in Allowed | Users with dial-in access enabled |
| Dial-in Not Allowed | Users with dial-in access denied |
| Recently Created Users | Users created in the last 30 days |
| Recently Deleted Users | Users deleted from Active Directory |
| Recently Modified Users | Users modified in the last 30 days |
| Users by Department | User accounts grouped by department |
| Users SID | Users and their security identifiers (SIDs) |
| Users with Home Folder | Users that have a home folder configured |
| Users with Logon Script | Users that have a logon script assigned |
| Users with Manager | Users that have a manager assigned in AD |
| Users with Photo | Users that have a photo configured in AD |
| Users with Profile Path | Users that have a profile path configured |
| Users without Home Folder | Users that do not have a home folder configured |
| Users without Logon Script | Users that do not have a logon script assigned |
| Users without Manager | Users that do not have a manager assigned in AD |
| Users without Photo | Users that do not have a photo configured in AD |
| Users without Profile Path | Users that do not have a profile path configured |
User Status
| Report | Description |
|---|---|
| Disabled Users | All disabled user accounts in Active Directory |
| Enabled Users | All enabled user accounts in Active Directory |
| Expired User Accounts | Users whose accounts have expired |
| Users Hidden from Address List | User accounts hidden from the Exchange Global Address List |
| Inactive Users | Users who have not logged on in 90 days or more |
| Locked Out Users | Users currently locked out of their accounts |
| Soon to Expire User Accounts | Users whose accounts will expire within 30 days |
| UAC Flags | Users and their UAC flag values |
| Users Not Protected from Deletion | Users not protected from accidental deletion |
| Users Protected from Deletion | Users protected from accidental deletion |
User Password Reports
| Report | Description |
|---|---|
| Bad Password Attempt Details | Failed login attempts per user per domain controller |
| Change Password at Next Logon | Users required to change password at next logon |
| Password Expired Users | Users whose passwords have expired |
| Password Last Set Date | Users and the date their password was last set |
| Password Not Required | Users with the password not required flag enabled |
| Password Set to Never Expire | Users with the password never expires flag enabled |
| Recent Password Changes | Users who changed their password in the last 30 days |
| Reversible Password Encryption Enabled | Users with reversible password encryption enabled |
| Soon to Expire Passwords | Users whose passwords will expire within 14 days |
| User Password Details | Detailed password status for all users |
| Users Can't Change Password | Users who cannot change their own password |
| Users with Old Password | Users who have not changed their password in 90 days or more |
| Users with Password Expiry | Users whose passwords have an expiry date set |
Logon Reports
| Report | Description |
|---|---|
| Logon Workstation Restrictions | Users with workstation logon restrictions configured |
| Never Logged On Users | Users who have never logged on to the domain |
| Recently Logged On Users | Users who have logged on in the last 30 days |
| True Last Logon Time | Accurate last logon time collected across all domain controllers |
| User Logon Hours | Users with logon hour restrictions configured |
Computers
| Report | Description |
|---|---|
| All Computers | All computer accounts in Active Directory |
| BitLocker Enabled | Computers with BitLocker recovery keys stored in Active Directory |
| BitLocker Not Enabled | Computers without BitLocker recovery keys in Active Directory |
| Computers by OS | Computer accounts grouped by operating system version |
| Disabled Computers | Computer accounts that are currently disabled in Active Directory |
| Domain Controllers | All domain controller computer accounts |
| Enabled Computers | Computer accounts that are currently enabled in Active Directory |
| Inactive Computers | Computers that have not logged on recently, so potential stale accounts |
| LAPS Enabled | Computers with LAPS (Local Administrator Password Solution) enabled |
| LAPS Not Enabled | Computers without LAPS, a potential security gap |
| LAPS Passwords | View LAPS passwords for computers (requires read permission on the LAPS attributes) |
| Managed Computers | Computers with a Managed By value set in Active Directory |
| Never Logged On Computers | Computers that have never logged on to the domain |
| True Last Logon Computers | Accurate last logon time for computers, collected across all domain controllers |
| Not Protected from Deletion | Computers not protected from accidental deletion in Active Directory |
| Protected from Deletion | Computers protected from accidental deletion in Active Directory |
| Recently Created Computers | Computers created in the last 30 days |
| Recently Deleted Computers | Computers deleted from Active Directory, from the Deleted Objects container |
| Recently Modified Computers | Computers modified in the last 30 days |
| Servers | All server computer accounts in Active Directory |
| Trusted for Delegation | Computers with the TRUSTED_FOR_DELEGATION flag set (unconstrained delegation) |
| Unmanaged Computers | Computers without a Managed By value in Active Directory |
| Workstations | All workstation computer accounts in Active Directory |
Groups
| Report | Description |
|---|---|
| All Groups | All groups in Active Directory |
| Default Groups | Default groups from the CN=Builtin and CN=Users containers |
| Distribution Groups | All distribution groups in Active Directory |
| Empty Groups | Groups with no members |
| Managed Groups | Groups that have a manager assigned |
| Groups Not Protected from Deletion | Groups not protected from accidental deletion |
| Groups Protected from Deletion | Groups protected from accidental deletion |
| Recently Created Groups | Groups created in the last 30 days |
| Recently Deleted Groups | Groups deleted from Active Directory, from the Deleted Objects container |
| Recently Modified Groups | Groups modified in the last 30 days |
| Security Groups | All security groups in Active Directory |
| Unmanaged Groups | Groups without a manager assigned |
Group Membership
| Report | Description |
|---|---|
| Empty Groups | Groups with no members |
| Group Members | All groups and their members |
| Group Member Summary | Groups with all members listed in a single row |
| Groups with Disabled User Members | Groups containing disabled user accounts |
| Groups with Nested Groups | Groups that have other groups as members |
| Large Groups | Groups sorted by member count, largest first |
| Nested Group Membership | All groups and their nested members |
| Privileged Group Members | Members of privileged administrative groups |
| User Group Membership | Users and the groups they belong to |
| User Membership Summary | Users and their group membership count |
| Users Not in Group | Select a group to find users who are not members of it |
| Users Primary Group | All users and their primary group |
| Users with No Groups | Users that are not a member of any group |
Security
| Report | Description |
|---|---|
| AD ACL Scanner | Audit permissions (ACLs) on Active Directory objects |
| AdminCount Orphans | Objects with adminCount=1 that are no longer members of any privileged group |
| Find Service Accounts | Scans remote computers for scheduled tasks and services running under domain accounts |
| Fine-Grained Password Policies | Password Settings Objects (PSOs) that define granular password policies for specific users or groups |
| Kerberoastable Accounts | User accounts with Service Principal Names (SPNs) set, which are vulnerable to Kerberoasting attacks |
| Local Certificates Report | Scans remote computers for locally installed certificates |
| Managed Service Accounts | Managed Service Accounts (MSA) and Group Managed Service Accounts (gMSA) in Active Directory |
| NTFS Permissions Report | Lists users and groups, folder access and permissions |
| Privileged Non-Expiring Passwords | Members of privileged groups whose passwords are set to never expire |
| Stale Privileged Accounts | Privileged group members that have not logged in within the selected time period |
| Unconstrained Delegation | User and computer accounts configured for unconstrained, constrained, or resource-based constrained delegation |
| Potential Service Accounts | User accounts that may be service accounts, based on naming, attributes and configuration |
| Users with SID History | User accounts that have SID History entries, which may indicate migration artifacts or privilege risks |
Group Policy
| Report | Description |
|---|---|
| All GPOs | All Group Policy Objects (GPOs) in the domain |
| Blocked Inheritance | Organizational Units with GPO inheritance blocked, so parent GPOs will not apply to them |
| Disabled GPO Links | GPO links that exist but are disabled, so the GPO will not apply at those locations |
| Duplicate/Conflicting GPOs | Settings configured in multiple GPOs, highlighting conflicts where the values differ |
| Empty GPOs | Group Policy Objects with no configured settings, detected via GPMC |
| Enforced GPOs | Group Policy Objects with enforcement enabled on one or more link locations |
| GPO Link Order | GPO link precedence per OU. A lower order number means higher priority, applied last and winning conflicts |
| GPO Permissions | Security permissions on each Group Policy Object: who can read, edit and delete GPOs |
| GPO Scripts | Logon, Logoff, Startup and Shutdown scripts configured in Group Policy Objects |
| Recently Modified GPOs | Group Policy Objects modified within a selected time period |
| Unused GPOs | Group Policy Objects that are not linked to any OU, site or domain |
Organizational Units
| Report | Description |
|---|---|
| All OUs | All Organizational Units in the domain |
| Deleted OUs | Organizational Units deleted from Active Directory, from the Deleted Objects container |
| Empty OUs | Organizational Units with no objects directly contained |
| Managed OUs | Organizational Units with a Managed By value configured |
| OUs Not Protected from Deletion | Organizational Units not protected from accidental deletion |
| OUs Protected from Deletion | Organizational Units protected from accidental deletion |
| OUs with Delegation | Organizational Units that have non-default delegated permissions applied |
| OUs with Linked GPOs | Organizational Units that have Group Policy Objects linked to them |
| OUs with Object Count | Number of objects directly contained in each Organizational Unit |
| Recently Created OUs | Organizational Units created within a selected time period |
| Recently Modified OUs | Organizational Units modified within a selected time period |
| Unmanaged OUs | Organizational Units with no Managed By value configured |
Contacts
| Report | Description |
|---|---|
| All Contacts | All contact objects in Active Directory |
| Recently Created Contacts | Contact objects created in the last 30 days |
| Recently Modified Contacts | Contact objects modified in the last 30 days |
| Managed Contacts | Contact objects that have a manager assigned |
| Unmanaged Contacts | Contact objects without a manager assigned |
| Contacts without Mail | Contact objects that do not have an email address |
