AD Pro Toolkit > Docs > Reports

Active Directory Reports

AD Pro Toolkit includes built-in Active Directory reports across 11 categories. Run one in a couple of clicks, export to CSV, Excel or PDF, and schedule it to run automatically.

How to run a report

  1. Click Reports and open a category in the sidebar, for example Users.
  2. Select a report and click Run.

Any report can be exported to CSV, Excel or PDF, and scheduled to run and email itself on a recurring basis. Most reports also let you pick an OU, choose columns, and filter the results in place.

Users

ReportDescription
All UsersAll user accounts in Active Directory
Count of Users in Each OUUser count breakdown by organizational unit
Dial-in AllowedUsers with dial-in access enabled
Dial-in Not AllowedUsers with dial-in access denied
Recently Created UsersUsers created in the last 30 days
Recently Deleted UsersUsers deleted from Active Directory
Recently Modified UsersUsers modified in the last 30 days
Users by DepartmentUser accounts grouped by department
Users SIDUsers and their security identifiers (SIDs)
Users with Home FolderUsers that have a home folder configured
Users with Logon ScriptUsers that have a logon script assigned
Users with ManagerUsers that have a manager assigned in AD
Users with PhotoUsers that have a photo configured in AD
Users with Profile PathUsers that have a profile path configured
Users without Home FolderUsers that do not have a home folder configured
Users without Logon ScriptUsers that do not have a logon script assigned
Users without ManagerUsers that do not have a manager assigned in AD
Users without PhotoUsers that do not have a photo configured in AD
Users without Profile PathUsers that do not have a profile path configured

User Status

ReportDescription
Disabled UsersAll disabled user accounts in Active Directory
Enabled UsersAll enabled user accounts in Active Directory
Expired User AccountsUsers whose accounts have expired
Users Hidden from Address ListUser accounts hidden from the Exchange Global Address List
Inactive UsersUsers who have not logged on in 90 days or more
Locked Out UsersUsers currently locked out of their accounts
Soon to Expire User AccountsUsers whose accounts will expire within 30 days
UAC FlagsUsers and their UAC flag values
Users Not Protected from DeletionUsers not protected from accidental deletion
Users Protected from DeletionUsers protected from accidental deletion

User Password Reports

ReportDescription
Bad Password Attempt DetailsFailed login attempts per user per domain controller
Change Password at Next LogonUsers required to change password at next logon
Password Expired UsersUsers whose passwords have expired
Password Last Set DateUsers and the date their password was last set
Password Not RequiredUsers with the password not required flag enabled
Password Set to Never ExpireUsers with the password never expires flag enabled
Recent Password ChangesUsers who changed their password in the last 30 days
Reversible Password Encryption EnabledUsers with reversible password encryption enabled
Soon to Expire PasswordsUsers whose passwords will expire within 14 days
User Password DetailsDetailed password status for all users
Users Can’t Change PasswordUsers who cannot change their own password
Users with Old PasswordUsers who have not changed their password in 90 days or more
Users with Password ExpiryUsers whose passwords have an expiry date set

Logon Reports

ReportDescription
Logon Workstation RestrictionsUsers with workstation logon restrictions configured
Never Logged On UsersUsers who have never logged on to the domain
Recently Logged On UsersUsers who have logged on in the last 30 days
True Last Logon TimeAccurate last logon time collected across all domain controllers
User Logon HoursUsers with logon hour restrictions configured

Computers

ReportDescription
All ComputersAll computer accounts in Active Directory
BitLocker EnabledComputers with BitLocker recovery keys stored in Active Directory
BitLocker Not EnabledComputers without BitLocker recovery keys in Active Directory
Computers by OSComputer accounts grouped by operating system version
Disabled ComputersComputer accounts that are currently disabled in Active Directory
Domain ControllersAll domain controller computer accounts
Enabled ComputersComputer accounts that are currently enabled in Active Directory
Inactive ComputersComputers that have not logged on recently, so potential stale accounts
LAPS EnabledComputers with LAPS (Local Administrator Password Solution) enabled
LAPS Not EnabledComputers without LAPS, a potential security gap
LAPS PasswordsView LAPS passwords for computers (requires read permission on the LAPS attributes)
Managed ComputersComputers with a Managed By value set in Active Directory
Never Logged On ComputersComputers that have never logged on to the domain
True Last Logon ComputersAccurate last logon time for computers, collected across all domain controllers
Not Protected from DeletionComputers not protected from accidental deletion in Active Directory
Protected from DeletionComputers protected from accidental deletion in Active Directory
Recently Created ComputersComputers created in the last 30 days
Recently Deleted ComputersComputers deleted from Active Directory, from the Deleted Objects container
Recently Modified ComputersComputers modified in the last 30 days
ServersAll server computer accounts in Active Directory
Trusted for DelegationComputers with the TRUSTED_FOR_DELEGATION flag set (unconstrained delegation)
Unmanaged ComputersComputers without a Managed By value in Active Directory
WorkstationsAll workstation computer accounts in Active Directory

Groups

ReportDescription
All GroupsAll groups in Active Directory
Default GroupsDefault groups from the CN=Builtin and CN=Users containers
Distribution GroupsAll distribution groups in Active Directory
Empty GroupsGroups with no members
Managed GroupsGroups that have a manager assigned
Groups Not Protected from DeletionGroups not protected from accidental deletion
Groups Protected from DeletionGroups protected from accidental deletion
Recently Created GroupsGroups created in the last 30 days
Recently Deleted GroupsGroups deleted from Active Directory, from the Deleted Objects container
Recently Modified GroupsGroups modified in the last 30 days
Security GroupsAll security groups in Active Directory
Unmanaged GroupsGroups without a manager assigned

Group Membership

ReportDescription
Empty GroupsGroups with no members
Group MembersAll groups and their members
Group Member SummaryGroups with all members listed in a single row
Groups with Disabled User MembersGroups containing disabled user accounts
Groups with Nested GroupsGroups that have other groups as members
Large GroupsGroups sorted by member count, largest first
Nested Group MembershipAll groups and their nested members
Privileged Group MembersMembers of privileged administrative groups
User Group MembershipUsers and the groups they belong to
User Membership SummaryUsers and their group membership count
Users Not in GroupSelect a group to find users who are not members of it
Users Primary GroupAll users and their primary group
Users with No GroupsUsers that are not a member of any group

Security

ReportDescription
AD ACL ScannerAudit permissions (ACLs) on Active Directory objects
AdminCount OrphansObjects with adminCount=1 that are no longer members of any privileged group
Find Service AccountsScans remote computers for scheduled tasks and services running under domain accounts
Fine-Grained Password PoliciesPassword Settings Objects (PSOs) that define granular password policies for specific users or groups
Kerberoastable AccountsUser accounts with Service Principal Names (SPNs) set, which are vulnerable to Kerberoasting attacks
Local Certificates ReportScans remote computers for locally installed certificates
Managed Service AccountsManaged Service Accounts (MSA) and Group Managed Service Accounts (gMSA) in Active Directory
NTFS Permissions ReportLists users and groups, folder access and permissions
Privileged Non-Expiring PasswordsMembers of privileged groups whose passwords are set to never expire
Stale Privileged AccountsPrivileged group members that have not logged in within the selected time period
Unconstrained DelegationUser and computer accounts configured for unconstrained, constrained, or resource-based constrained delegation
Potential Service AccountsUser accounts that may be service accounts, based on naming, attributes and configuration
Users with SID HistoryUser accounts that have SID History entries, which may indicate migration artifacts or privilege risks

Domain-wide checks such as the krbtgt password age, tombstone lifetime, forest functional level, duplicate SPNs and Protected Users are not separate reports. They run as checks inside AD Security Assessment, on the Security tab.

Group Policy

ReportDescription
All GPOsAll Group Policy Objects (GPOs) in the domain
Blocked InheritanceOrganizational Units with GPO inheritance blocked, so parent GPOs will not apply to them
Disabled GPO LinksGPO links that exist but are disabled, so the GPO will not apply at those locations
Duplicate/Conflicting GPOsSettings configured in multiple GPOs, highlighting conflicts where the values differ
Empty GPOsGroup Policy Objects with no configured settings, detected via GPMC
Enforced GPOsGroup Policy Objects with enforcement enabled on one or more link locations
GPO Link OrderGPO link precedence per OU. A lower order number means higher priority, applied last and winning conflicts
GPO PermissionsSecurity permissions on each Group Policy Object: who can read, edit and delete GPOs
GPO ScriptsLogon, Logoff, Startup and Shutdown scripts configured in Group Policy Objects
Recently Modified GPOsGroup Policy Objects modified within a selected time period
Unused GPOsGroup Policy Objects that are not linked to any OU, site or domain

Organizational Units

ReportDescription
All OUsAll Organizational Units in the domain
Deleted OUsOrganizational Units deleted from Active Directory, from the Deleted Objects container
Empty OUsOrganizational Units with no objects directly contained
Managed OUsOrganizational Units with a Managed By value configured
OUs Not Protected from DeletionOrganizational Units not protected from accidental deletion
OUs Protected from DeletionOrganizational Units protected from accidental deletion
OUs with DelegationOrganizational Units that have non-default delegated permissions applied
OUs with Linked GPOsOrganizational Units that have Group Policy Objects linked to them
OUs with Object CountNumber of objects directly contained in each Organizational Unit
Recently Created OUsOrganizational Units created within a selected time period
Recently Modified OUsOrganizational Units modified within a selected time period
Unmanaged OUsOrganizational Units with no Managed By value configured

Contacts

ReportDescription
All ContactsAll contact objects in Active Directory
Recently Created ContactsContact objects created in the last 30 days
Recently Modified ContactsContact objects modified in the last 30 days
Managed ContactsContact objects that have a manager assigned
Unmanaged ContactsContact objects without a manager assigned
Contacts without MailContact objects that do not have an email address

Active Directory Pro · AD Pro Toolkit docs · Download · Pricing