AD Reports Features
Simplify Active Directory and Azure management with precision reporting. Explore every feature that makes AD Reports the tool of choice for IT professionals.
Report History & Compare New
Save any AD or Azure report as a baseline and compare it later to see exactly what changed in
your directory. The new Diff tab shows three sub-tabs — Added,
Removed, and Changed — with side-by-side (was) and
(now) columns. Snapshots persist across restarts so you can compare today's results
against last week, last month, or your last security audit. Works for every AD report and every
Azure report.
Hybrid Identity Gap Analysis New
Brand-new top-level page that cross-references on-prem Active Directory users with your Entra ID tenant and surfaces the mismatches. Six pre-built views answer the questions on-prem reporting alone can't: All Hybrid Users, Cloud-Only Privileged Admins, On-Prem Accounts NOT Syncing, UPN Suffix Mismatches, immutableID Conflicts, and Disabled On-Prem / Enabled in Entra. Color-coded match status, header summary counts, timestamped CSV / Excel exports.
Hybrid Identity Gap Analysis
Azure Devices & Stale Guest Users New
Two new free-tier Azure reports — no P1 / P2 license required. The brand-new Devices tab inventories every device registered in your Entra tenant, with views for All / Enabled / Disabled / Stale (90 days) and Intune-aware compliance and management columns. Stale Guest Users (90 days) lists external collaborators who got an invitation, were never reviewed, and quietly accumulate — common cleanup target.
Azure Device Reports
Real-Time Dashboard
Monitor your entire Active Directory and Azure Entra ID environment from a single, live dashboard. View key performance indicators at the top — total users, groups, computers, locked-out accounts, expiring passwords, stale accounts, disabled users, and critical issues. Dive deeper with dedicated widgets for password health, domain controller status, privileged accounts, security alerts, account lockout trends, GPO and group changes, domain summary, and Azure Entra ID sync and group metrics. Every widget supports live data refresh and one-click navigation to the underlying report.
How to Use the Dashboard
300+ Predefined Reports
AD Reports offers a comprehensive collection of over 300 predefined reports, covering a wide range of Active Directory elements such as Users, Groups, Organizational Units, Computers, Group Policy Objects (GPO), Contacts, Exchange, Printers, and NTFS permissions. These predefined reports provide immediate insights into various aspects of your Active Directory environment. Customize any existing report or create entirely new reports from scratch and save them as custom reports.
Report Library
Azure Entra ID Reporting
Extend your reporting capabilities to the cloud with comprehensive Azure Entra ID (formerly Azure Active Directory) reporting. Generate detailed reports for cloud users with the same ease as on-premises Active Directory. Access pre-built user reports including All Users, Enabled Users, Disabled Users, Admins, and Guest Users. Create custom reports with advanced OData filters compatible with Microsoft Graph API. Select from 42 Microsoft Entra ID properties organized by category.
How to Run Azure User Reports
Azure Report Configuration Tool
The Azure Report Configuration tool provides a powerful yet intuitive interface for creating custom Azure reports. Select Microsoft Entra ID properties organized into 9 categories: Activity, Additional, Contact, Identity, Licensing, Location, Personal, Security, and Status. Build complex OData filters with a visual query builder that generates Microsoft Graph API-compatible syntax. The built-in configuration summary validates your settings, displays the estimated Graph API call, and provides performance estimates before you run the report.
How to Create Custom Azure Reports
Azure Authentication Management
Manage your Azure authentication with ease through the dedicated Azure Authentication Settings. Sign in with your Microsoft admin account to grant necessary permissions for accessing Azure Entra ID data. View real-time authentication status including signed-in account and token validity. Perform actions such as signing out to switch accounts, refreshing tokens without re-authentication, testing connectivity to Microsoft Entra ID, and reviewing granted permissions. Authentication is separate from email settings and is used solely for accessing Microsoft Entra ID data.
Azure Authentication Settings
Built-in Scheduler
A built-in reporting scheduler allows you to schedule and automate the generation and delivery of reports at specified intervals. Instead of manually running and distributing reports, the scheduler automates the process, saving time and ensuring timely delivery. Schedule your reports at a specific time or on a continuous basis at intervals of hours, days, weeks or months.
How to Schedule Reports
Report Wizard
Report Wizard provides a user-friendly interface for generating comprehensive reports on various aspects of your Active Directory infrastructure. It simplifies the process of querying and retrieving information and presents it in a structured and customizable format. Start your search from any container or search the entire domain. Select Search Root, Search Scope, LDAP Attributes (predefined or all), Membership settings, and more.
How to use Report Wizard
OData Filter Builder for Azure
The OData Filter Builder for Azure reports provides a visual interface for constructing complex filters compatible with Microsoft Graph API. Build filters using 16 available filterable properties without needing to know OData syntax. Combine multiple conditions using And/Or logic. The real-time OData Filter Preview displays and validates the generated syntax. Test your filters against your actual Microsoft Entra ID tenant before running reports.
How to use OData Filter Builder
Save Report for All Domains
When generating reports, you have the flexibility to save the report settings for either the selected domain or all domains within the current forest. This allows you to customize the report generation process to focus on a specific domain or encompass all domains within the forest, depending on your reporting requirements and scope.
How to Create Custom Reports
Export Reports
Export your generated reports to a multitude of formats including PDF, CSV, TXT, XLS, RTF, HTML, and more. Select the format that best suits your needs for efficient collaboration, data examination, and archiving. Azure reports support the same export functionality, allowing you to export cloud-based reports in any available format for consistent reporting across your entire infrastructure.
How to Export a Report
Built-in LDAP Query Builder
The LDAP query builder simplifies the process of constructing LDAP queries to search and retrieve information from Active Directory. It provides a user-friendly interface to generate complex LDAP queries without requiring in-depth knowledge of the LDAP syntax. Create your own LDAP queries and apply them to any report.
How to use Report Wizard
True Last Logon
The "True Last Logon" refers to the most recent logon time of a user account or computer object. It represents the actual last logon event recorded in the Active Directory database, taking into account the replication delay between domain controllers. It includes non-replicated attributes like lastLogon, badPasswordTime, badPwdCount, logonCount, and whenChanged. The "True Locked Out" report is also based on domain lockout policy.
Logon Status Reports
Exclude Domain Controllers
Selectively exclude domain controllers from the scanning process. Choose only the domain controllers you wish to scan, allowing for a targeted and efficient approach. AD Reports automatically eliminates inaccessible domain controllers from the scanning operation, resulting in improved performance and streamlined results.
How to Exclude Domain Controllers
User Membership
Load the direct groups a user belongs to, including both security and distribution groups, nested groups, and the user's primary group. Specify whether to load only Distinguished Names or select and load any predefined attributes associated with the user's membership. Tailor the information retrieved to suit your specific needs and reporting requirements.
How to Load User Membership
Group Members
Load group members directly or including nested group members for a comprehensive view of group membership. Select any predefined attributes related to the members for loading. Translate Foreign Security Principals to NT Accounts for seamless integration, and display the number of members for each loaded group, providing valuable insights into group sizes.
How to Load Group Members
Selected Object Information
With just a single mouse click, gain instant access to a wealth of detailed information about any selected Active Directory object. This includes General Information such as name, address, organization, and contact details. Retrieve Security Information covering account and password status. Explore Group Membership details and all available LDAP Attributes along with their corresponding values — directly from the report grid.
Customizable Print Preview
Preview and adjust the layout, formatting, and content of a report before printing. Assess how the document will appear on paper and make modifications to ensure the desired print output. Apply your own watermark, create custom headers and footers, export and send a report via e-mail in any available format. Both on-premises AD and Azure reports support full print customization.
Audit Module — Redesigned
A dedicated top-level page with a master/detail layout: profiles list and reports-in-profile preview on the left, full-height result tabs on the right. Ships with 7 built-in profiles including Kerberos Attack Surface and Legacy OS & Stale Systems. The audit runner executes up to 4 reports in parallel for 3–4× faster audits. Schedule any profile for unattended execution with multi-sheet Excel export and HTML email summary delivery.
How to Use the Audit Module
Azure Applications & Access Reports
Six new reports for auditing your Microsoft Entra ID application landscape — no P1/P2 license required. List all app registrations, find apps with secrets or certificates expiring within 30 days, audit service principals and directory role assignments, and review license utilization with assigned-vs-consumed metrics.
Azure Applications & Access Reports
Report Results Tab
Run multiple reports sequentially and keep every result in persistent, closeable tabs with color-coded status icons. Export from any saved snapshot via the ribbon toolbar — Excel, CSV, Clean XLSX, PDF, or multi-sheet workbook. Configurable max tabs (default 20) with automatic FIFO cleanup.
How to Use the Results Tab
Scheduler Job History
Persistent execution history for every scheduled report and audit profile. A collapsible dock panel on the Scheduler page shows color-coded status (Success, Partial, Failed, Empty), duration, record count, export path, email status, and error details. Auto-refreshes every 30 seconds to show Windows Service activity. Failed reports automatically retry once after a 30-second delay.
Scheduler Job History
Ready to Get Started?
Download the free 14-day trial and experience every feature firsthand. $50 discount included with your trial.