Active Directory Reports

AD Pro Toolkit includes built-in Active Directory reports across 11 categories. Run one in a couple of clicks, export to CSV, Excel or PDF, and schedule it to run automatically.

How to run a report

Any report can be exported to CSV, Excel or PDF, and scheduled to run and email itself on a recurring basis. Most reports also let you pick an OU, choose columns, and filter the results in place.

  1. Click Reports and open a category in the sidebar, for example Users.
  2. Select a report and click Run.

Users

Report Description
All Users All user accounts in Active Directory
Count of Users in Each OU User count breakdown by organizational unit
Dial-in Allowed Users with dial-in access enabled
Dial-in Not Allowed Users with dial-in access denied
Recently Created Users Users created in the last 30 days
Recently Deleted Users Users deleted from Active Directory
Recently Modified Users Users modified in the last 30 days
Users by Department User accounts grouped by department
Users SID Users and their security identifiers (SIDs)
Users with Home Folder Users that have a home folder configured
Users with Logon Script Users that have a logon script assigned
Users with Manager Users that have a manager assigned in AD
Users with Photo Users that have a photo configured in AD
Users with Profile Path Users that have a profile path configured
Users without Home Folder Users that do not have a home folder configured
Users without Logon Script Users that do not have a logon script assigned
Users without Manager Users that do not have a manager assigned in AD
Users without Photo Users that do not have a photo configured in AD
Users without Profile Path Users that do not have a profile path configured

User Status

Report Description
Disabled Users All disabled user accounts in Active Directory
Enabled Users All enabled user accounts in Active Directory
Expired User Accounts Users whose accounts have expired
Users Hidden from Address List User accounts hidden from the Exchange Global Address List
Inactive Users Users who have not logged on in 90 days or more
Locked Out Users Users currently locked out of their accounts
Soon to Expire User Accounts Users whose accounts will expire within 30 days
UAC Flags Users and their UAC flag values
Users Not Protected from Deletion Users not protected from accidental deletion
Users Protected from Deletion Users protected from accidental deletion

User Password Reports

Report Description
Bad Password Attempt Details Failed login attempts per user per domain controller
Change Password at Next Logon Users required to change password at next logon
Password Expired Users Users whose passwords have expired
Password Last Set Date Users and the date their password was last set
Password Not Required Users with the password not required flag enabled
Password Set to Never Expire Users with the password never expires flag enabled
Recent Password Changes Users who changed their password in the last 30 days
Reversible Password Encryption Enabled Users with reversible password encryption enabled
Soon to Expire Passwords Users whose passwords will expire within 14 days
User Password Details Detailed password status for all users
Users Can't Change Password Users who cannot change their own password
Users with Old Password Users who have not changed their password in 90 days or more
Users with Password Expiry Users whose passwords have an expiry date set

Logon Reports

Report Description
Logon Workstation Restrictions Users with workstation logon restrictions configured
Never Logged On Users Users who have never logged on to the domain
Recently Logged On Users Users who have logged on in the last 30 days
True Last Logon Time Accurate last logon time collected across all domain controllers
User Logon Hours Users with logon hour restrictions configured

Computers

Report Description
All Computers All computer accounts in Active Directory
BitLocker Enabled Computers with BitLocker recovery keys stored in Active Directory
BitLocker Not Enabled Computers without BitLocker recovery keys in Active Directory
Computers by OS Computer accounts grouped by operating system version
Disabled Computers Computer accounts that are currently disabled in Active Directory
Domain Controllers All domain controller computer accounts
Enabled Computers Computer accounts that are currently enabled in Active Directory
Inactive Computers Computers that have not logged on recently, so potential stale accounts
LAPS Enabled Computers with LAPS (Local Administrator Password Solution) enabled
LAPS Not Enabled Computers without LAPS, a potential security gap
LAPS Passwords View LAPS passwords for computers (requires read permission on the LAPS attributes)
Managed Computers Computers with a Managed By value set in Active Directory
Never Logged On Computers Computers that have never logged on to the domain
True Last Logon Computers Accurate last logon time for computers, collected across all domain controllers
Not Protected from Deletion Computers not protected from accidental deletion in Active Directory
Protected from Deletion Computers protected from accidental deletion in Active Directory
Recently Created Computers Computers created in the last 30 days
Recently Deleted Computers Computers deleted from Active Directory, from the Deleted Objects container
Recently Modified Computers Computers modified in the last 30 days
Servers All server computer accounts in Active Directory
Trusted for Delegation Computers with the TRUSTED_FOR_DELEGATION flag set (unconstrained delegation)
Unmanaged Computers Computers without a Managed By value in Active Directory
Workstations All workstation computer accounts in Active Directory

Groups

Report Description
All Groups All groups in Active Directory
Default Groups Default groups from the CN=Builtin and CN=Users containers
Distribution Groups All distribution groups in Active Directory
Empty Groups Groups with no members
Managed Groups Groups that have a manager assigned
Groups Not Protected from Deletion Groups not protected from accidental deletion
Groups Protected from Deletion Groups protected from accidental deletion
Recently Created Groups Groups created in the last 30 days
Recently Deleted Groups Groups deleted from Active Directory, from the Deleted Objects container
Recently Modified Groups Groups modified in the last 30 days
Security Groups All security groups in Active Directory
Unmanaged Groups Groups without a manager assigned

Group Membership

Report Description
Empty Groups Groups with no members
Group Members All groups and their members
Group Member Summary Groups with all members listed in a single row
Groups with Disabled User Members Groups containing disabled user accounts
Groups with Nested Groups Groups that have other groups as members
Large Groups Groups sorted by member count, largest first
Nested Group Membership All groups and their nested members
Privileged Group Members Members of privileged administrative groups
User Group Membership Users and the groups they belong to
User Membership Summary Users and their group membership count
Users Not in Group Select a group to find users who are not members of it
Users Primary Group All users and their primary group
Users with No Groups Users that are not a member of any group

Security

Report Description
AD ACL Scanner Audit permissions (ACLs) on Active Directory objects
AdminCount Orphans Objects with adminCount=1 that are no longer members of any privileged group
Find Service Accounts Scans remote computers for scheduled tasks and services running under domain accounts
Fine-Grained Password Policies Password Settings Objects (PSOs) that define granular password policies for specific users or groups
Kerberoastable Accounts User accounts with Service Principal Names (SPNs) set, which are vulnerable to Kerberoasting attacks
Local Certificates Report Scans remote computers for locally installed certificates
Managed Service Accounts Managed Service Accounts (MSA) and Group Managed Service Accounts (gMSA) in Active Directory
NTFS Permissions Report Lists users and groups, folder access and permissions
Privileged Non-Expiring Passwords Members of privileged groups whose passwords are set to never expire
Stale Privileged Accounts Privileged group members that have not logged in within the selected time period
Unconstrained Delegation User and computer accounts configured for unconstrained, constrained, or resource-based constrained delegation
Potential Service Accounts User accounts that may be service accounts, based on naming, attributes and configuration
Users with SID History User accounts that have SID History entries, which may indicate migration artifacts or privilege risks

Group Policy

Report Description
All GPOs All Group Policy Objects (GPOs) in the domain
Blocked Inheritance Organizational Units with GPO inheritance blocked, so parent GPOs will not apply to them
Disabled GPO Links GPO links that exist but are disabled, so the GPO will not apply at those locations
Duplicate/Conflicting GPOs Settings configured in multiple GPOs, highlighting conflicts where the values differ
Empty GPOs Group Policy Objects with no configured settings, detected via GPMC
Enforced GPOs Group Policy Objects with enforcement enabled on one or more link locations
GPO Link Order GPO link precedence per OU. A lower order number means higher priority, applied last and winning conflicts
GPO Permissions Security permissions on each Group Policy Object: who can read, edit and delete GPOs
GPO Scripts Logon, Logoff, Startup and Shutdown scripts configured in Group Policy Objects
Recently Modified GPOs Group Policy Objects modified within a selected time period
Unused GPOs Group Policy Objects that are not linked to any OU, site or domain

Organizational Units

Report Description
All OUs All Organizational Units in the domain
Deleted OUs Organizational Units deleted from Active Directory, from the Deleted Objects container
Empty OUs Organizational Units with no objects directly contained
Managed OUs Organizational Units with a Managed By value configured
OUs Not Protected from Deletion Organizational Units not protected from accidental deletion
OUs Protected from Deletion Organizational Units protected from accidental deletion
OUs with Delegation Organizational Units that have non-default delegated permissions applied
OUs with Linked GPOs Organizational Units that have Group Policy Objects linked to them
OUs with Object Count Number of objects directly contained in each Organizational Unit
Recently Created OUs Organizational Units created within a selected time period
Recently Modified OUs Organizational Units modified within a selected time period
Unmanaged OUs Organizational Units with no Managed By value configured

Contacts

Report Description
All Contacts All contact objects in Active Directory
Recently Created Contacts Contact objects created in the last 30 days
Recently Modified Contacts Contact objects modified in the last 30 days
Managed Contacts Contact objects that have a manager assigned
Unmanaged Contacts Contact objects without a manager assigned
Contacts without Mail Contact objects that do not have an email address