- Published on
Free — read-only · On-premises · No agents on your DCs
Find the accounts your Active Directory forgot about.
SysFlint AD reports on the disabled, stale, and over-privileged accounts sitting in your domain, across every dashboard and every report, on unlimited domains. It runs entirely inside your own network, and reading your directory costs nothing — a free key is only needed to run reports on a schedule or write a change back to AD.
What it reports on
Six reports covering the questions an auditor, an insurer, or a pentest report is most likely to ask first.
Disabled account reports
Every disabled account, with the OU it lives in, when it was last used, and how long it has been sitting there.
Learn more →Stale and inactive account detection
Enabled accounts that nobody has logged into for 30, 60, or 90+ days — the ones that are still a live attack surface.
Learn more →Privileged group auditing
Who is in Domain Admins, Enterprise Admins, and Schema Admins — including nested membership and accounts that should not be there.
Learn more →Password and expiry reporting
Accounts with "password never expires", passwords older than your policy, and accounts that never set one at all.
Learn more →Scheduled reports by email
Daily, weekly, or monthly runs delivered to the right inbox automatically. No Task Scheduler job for you to babysit.
Learn more →Multi-domain and forest coverage
Enumerate every domain in the forest in one pass and get one consolidated report instead of one per domain.
Learn more →
How it works
Install on a domain-joined machine
One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.
Point it at your domain
It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.
Read the report, then schedule it
Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.
On-premises, and read-only
An auditing tool that ships your directory contents somewhere else is a strange way to improve your security posture.
- Runs entirely on hardware you control — there is no SysFlint cloud service to sign up for.
- No directory data, account names, or report contents are transmitted to SysFlint.
- Read-only for every report and every diff: nothing is written to your directory just by looking at one. The one exception is deliberate — restoring a snapshot back to AD — and it only ever runs on changes you explicitly select and confirm, never automatically.
- No agents and no schema extensions on domain controllers.
- Works in air-gapped and disconnected environments.
Handed one of these jobs?
From the blog
All posts →- A PowerShell script to report each Active Directory user's assigned manager, resolved to a readable name, flagging anyone with no manager set.
- Published on
LastLogonDate can be up to two weeks stale. This PowerShell script queries the non-replicated LastLogon attribute on every domain controller directly and returns the real answer.- Published on
A PowerShell script to list every user in a specific Active Directory OU, including sub-OUs by default, before applying a GPO or handing the OU off to a delegated admin.
Get SysFlint AD
Free — read-only. No per-user pricing, no seat counts, no trial timer for reporting. A free evaluation key unlocks two things: scheduled exports and writing a diff back to AD — see the pricing page.