Skip to content

Active Directory Security Reports

The AD Pro Toolkit includes a collection of pre-built security reports. These reports provide quick insights into account risks, privileged access, password issues, configuration weaknesses, and other security-relevant conditions across your AD environment. They help administrators identify vulnerabilities, audit compliance, and maintain a secure directory.

  1. Click Reports > Security Reports
  2. Select a report and click the run button.

select security reports

Report nameDescription
AD ACL ScannerGets the ACLs on Active Directory objects. Shows delegated permissions.
Local CertificatesScans remote computers to get locally installed certificates.
NTFS PermissionsLists users and groups, folder access and permissions.
FirewallScan remote computers and gets the firewall status and rules.
Service AccountsScan remote computers and get schedule tasks and services.
Admin with old passwordsList of admins who have not changed their password in the last 180 days.
Admins with Kerberos (SPNs)Reading ServicePrincipalName of the computer if it is the memberOf Domain Admins group.
Default Domain AdministratorDefault administrator account, last logon and password reset date.
Built-In Privileged GroupsEnterprise Admins, Domain Admins, Administrators, Schema Admins, Group Policy Creator Owners.
Krbtgt accountLists the password last set date and status for krbtgt account.
Fine grained password policyLists all fine grained password policies and settings.
Protected UsersList the members (users) of the Protected Users group.
Tombstone lifetimeLists the Tombstone lifetime of the domain.
Forest Functional LevelLists the forest functional level.
Duplicate Service Principal Names (SPNs)Getting results from the SetSPN -X -F command.
Bitlocker Recovery KeysLists bitlocker recovery keys.
LAPS passwordsLists the LAPS password for computer accounts.
LAPS passwords (Legacy)Lists the LAPS password for computer accounts (old LAPS version).
Reversible EncryptionLists users who store passwords using reversible encryption.
Use only Kerberos DES encryptionLists users whose account option (Use only Kerberos DES encryption types for this account) is enabled.
Do not require kerberos preauthenticationLists users whose account option (Do not require kerberos preauthentication) is enabled.
SID historyLists users who have SID History.