Product Features

AD Reports Features

Simplify Active Directory and Azure management with precision reporting. Explore every feature that makes AD Reports the tool of choice for IT professionals.

Compare & Trend

Report History & Compare New

Save any AD or Azure report as a baseline and compare it later to see exactly what changed in your directory. The new Diff tab shows three sub-tabs — Added, Removed, and Changed — with side-by-side (was) and (now) columns. Snapshots persist across restarts so you can compare today's results against last week, last month, or your last security audit. Works for every AD report and every Azure report.

Save & Compare Report Snapshots
AD Reports Report History and Diff Compare view
Hybrid Identity

Hybrid Identity Gap Analysis New

Brand-new top-level page that cross-references on-prem Active Directory users with your Entra ID tenant and surfaces the mismatches. Six pre-built views answer the questions on-prem reporting alone can't: All Hybrid Users, Cloud-Only Privileged Admins, On-Prem Accounts NOT Syncing, UPN Suffix Mismatches, immutableID Conflicts, and Disabled On-Prem / Enabled in Entra. Color-coded match status, header summary counts, timestamped CSV / Excel exports.

Hybrid Identity Gap Analysis
AD Reports Hybrid Identity Gap Analysis
Azure Reports

Azure Devices & Stale Guest Users New

Two new free-tier Azure reports — no P1 / P2 license required. The brand-new Devices tab inventories every device registered in your Entra tenant, with views for All / Enabled / Disabled / Stale (90 days) and Intune-aware compliance and management columns. Stale Guest Users (90 days) lists external collaborators who got an invitation, were never reviewed, and quietly accumulate — common cleanup target.

Azure Device Reports
AD Reports Azure Devices Tab
Dashboard

Real-Time Dashboard

Monitor your entire Active Directory and Azure Entra ID environment from a single, live dashboard. View key performance indicators at the top — total users, groups, computers, locked-out accounts, expiring passwords, stale accounts, disabled users, and critical issues. Dive deeper with dedicated widgets for password health, domain controller status, privileged accounts, security alerts, account lockout trends, GPO and group changes, domain summary, and Azure Entra ID sync and group metrics. Every widget supports live data refresh and one-click navigation to the underlying report.

How to Use the Dashboard
AD Reports Real-Time Dashboard
Report Library

300+ Predefined Reports

AD Reports offers a comprehensive collection of over 300 predefined reports, covering a wide range of Active Directory elements such as Users, Groups, Organizational Units, Computers, Group Policy Objects (GPO), Contacts, Exchange, Printers, and NTFS permissions. These predefined reports provide immediate insights into various aspects of your Active Directory environment. Customize any existing report or create entirely new reports from scratch and save them as custom reports.

Report Library
AD Reports Predefined Reports
Azure Integration

Azure Entra ID Reporting

Extend your reporting capabilities to the cloud with comprehensive Azure Entra ID (formerly Azure Active Directory) reporting. Generate detailed reports for cloud users with the same ease as on-premises Active Directory. Access pre-built user reports including All Users, Enabled Users, Disabled Users, Admins, and Guest Users. Create custom reports with advanced OData filters compatible with Microsoft Graph API. Select from 42 Microsoft Entra ID properties organized by category.

How to Run Azure User Reports
Azure Reports for Azure Entra ID
Configuration

Azure Report Configuration Tool

The Azure Report Configuration tool provides a powerful yet intuitive interface for creating custom Azure reports. Select Microsoft Entra ID properties organized into 9 categories: Activity, Additional, Contact, Identity, Licensing, Location, Personal, Security, and Status. Build complex OData filters with a visual query builder that generates Microsoft Graph API-compatible syntax. The built-in configuration summary validates your settings, displays the estimated Graph API call, and provides performance estimates before you run the report.

How to Create Custom Azure Reports
Azure Report Configuration
Authentication

Azure Authentication Management

Manage your Azure authentication with ease through the dedicated Azure Authentication Settings. Sign in with your Microsoft admin account to grant necessary permissions for accessing Azure Entra ID data. View real-time authentication status including signed-in account and token validity. Perform actions such as signing out to switch accounts, refreshing tokens without re-authentication, testing connectivity to Microsoft Entra ID, and reviewing granted permissions. Authentication is separate from email settings and is used solely for accessing Microsoft Entra ID data.

Azure Authentication Settings
Azure Authentication Settings
Automation

Built-in Scheduler

A built-in reporting scheduler allows you to schedule and automate the generation and delivery of reports at specified intervals. Instead of manually running and distributing reports, the scheduler automates the process, saving time and ensuring timely delivery. Schedule your reports at a specific time or on a continuous basis at intervals of hours, days, weeks or months.

How to Schedule Reports
AD Reports Built-in Scheduler
Wizard

Report Wizard

Report Wizard provides a user-friendly interface for generating comprehensive reports on various aspects of your Active Directory infrastructure. It simplifies the process of querying and retrieving information and presents it in a structured and customizable format. Start your search from any container or search the entire domain. Select Search Root, Search Scope, LDAP Attributes (predefined or all), Membership settings, and more.

How to use Report Wizard
AD Reports Report Wizard
OData Filters

OData Filter Builder for Azure

The OData Filter Builder for Azure reports provides a visual interface for constructing complex filters compatible with Microsoft Graph API. Build filters using 16 available filterable properties without needing to know OData syntax. Combine multiple conditions using And/Or logic. The real-time OData Filter Preview displays and validates the generated syntax. Test your filters against your actual Microsoft Entra ID tenant before running reports.

How to use OData Filter Builder
Azure OData Filter Builder
Multi-Domain

Save Report for All Domains

When generating reports, you have the flexibility to save the report settings for either the selected domain or all domains within the current forest. This allows you to customize the report generation process to focus on a specific domain or encompass all domains within the forest, depending on your reporting requirements and scope.

How to Create Custom Reports
AD Reports Save for All Domains
Export

Export Reports

Export your generated reports to a multitude of formats including PDF, CSV, TXT, XLS, RTF, HTML, and more. Select the format that best suits your needs for efficient collaboration, data examination, and archiving. Azure reports support the same export functionality, allowing you to export cloud-based reports in any available format for consistent reporting across your entire infrastructure.

How to Export a Report
AD Reports Export Formats
Query Builder

Built-in LDAP Query Builder

The LDAP query builder simplifies the process of constructing LDAP queries to search and retrieve information from Active Directory. It provides a user-friendly interface to generate complex LDAP queries without requiring in-depth knowledge of the LDAP syntax. Create your own LDAP queries and apply them to any report.

How to use Report Wizard
AD Reports LDAP Query Builder
Advanced Attributes

True Last Logon

The "True Last Logon" refers to the most recent logon time of a user account or computer object. It represents the actual last logon event recorded in the Active Directory database, taking into account the replication delay between domain controllers. It includes non-replicated attributes like lastLogon, badPasswordTime, badPwdCount, logonCount, and whenChanged. The "True Locked Out" report is also based on domain lockout policy.

Logon Status Reports
AD Reports True Last Logon
Performance

Exclude Domain Controllers

Selectively exclude domain controllers from the scanning process. Choose only the domain controllers you wish to scan, allowing for a targeted and efficient approach. AD Reports automatically eliminates inaccessible domain controllers from the scanning operation, resulting in improved performance and streamlined results.

How to Exclude Domain Controllers
AD Reports Exclude Domain Controllers
Membership

User Membership

Load the direct groups a user belongs to, including both security and distribution groups, nested groups, and the user's primary group. Specify whether to load only Distinguished Names or select and load any predefined attributes associated with the user's membership. Tailor the information retrieved to suit your specific needs and reporting requirements.

How to Load User Membership
AD Reports User Membership
Group Analysis

Group Members

Load group members directly or including nested group members for a comprehensive view of group membership. Select any predefined attributes related to the members for loading. Translate Foreign Security Principals to NT Accounts for seamless integration, and display the number of members for each loaded group, providing valuable insights into group sizes.

How to Load Group Members
AD Reports Group Members
Object Details

Selected Object Information

With just a single mouse click, gain instant access to a wealth of detailed information about any selected Active Directory object. This includes General Information such as name, address, organization, and contact details. Retrieve Security Information covering account and password status. Explore Group Membership details and all available LDAP Attributes along with their corresponding values — directly from the report grid.

AD Reports Selected Object Information
Print & Preview

Customizable Print Preview

Preview and adjust the layout, formatting, and content of a report before printing. Assess how the document will appear on paper and make modifications to ensure the desired print output. Apply your own watermark, create custom headers and footers, export and send a report via e-mail in any available format. Both on-premises AD and Azure reports support full print customization.

AD Reports Customizable Print Preview
Batch Auditing

Audit Module — Redesigned

A dedicated top-level page with a master/detail layout: profiles list and reports-in-profile preview on the left, full-height result tabs on the right. Ships with 7 built-in profiles including Kerberos Attack Surface and Legacy OS & Stale Systems. The audit runner executes up to 4 reports in parallel for 3–4× faster audits. Schedule any profile for unattended execution with multi-sheet Excel export and HTML email summary delivery.

How to Use the Audit Module
AD Reports Audit Module
Azure Apps

Azure Applications & Access Reports

Six new reports for auditing your Microsoft Entra ID application landscape — no P1/P2 license required. List all app registrations, find apps with secrets or certificates expiring within 30 days, audit service principals and directory role assignments, and review license utilization with assigned-vs-consumed metrics.

Azure Applications & Access Reports
Azure Applications and Access Reports
Results

Report Results Tab

Run multiple reports sequentially and keep every result in persistent, closeable tabs with color-coded status icons. Export from any saved snapshot via the ribbon toolbar — Excel, CSV, Clean XLSX, PDF, or multi-sheet workbook. Configurable max tabs (default 20) with automatic FIFO cleanup.

How to Use the Results Tab
AD Reports Report Results Tab
Job History

Scheduler Job History

Persistent execution history for every scheduled report and audit profile. A collapsible dock panel on the Scheduler page shows color-coded status (Success, Partial, Failed, Empty), duration, record count, export path, email status, and error details. Auto-refreshes every 30 seconds to show Windows Service activity. Failed reports automatically retry once after a 30-second delay.

Scheduler Job History
AD Reports Scheduler Job History

Ready to Get Started?

Download the free 14-day trial and experience every feature firsthand. $50 discount included with your trial.