Free, forever · On-premises · No agents on your DCs

Find the accounts your Active Directory forgot about.

On-Prem AD Auditor reports on the disabled, stale, and over-privileged accounts sitting in your domain — and emails those reports on a schedule. It runs entirely inside your own network, and it costs nothing.

What it reports on

Six reports covering the questions an auditor, an insurer, or a pentest report is most likely to ask first.

How it works

  1. Install on a domain-joined machine

    One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.

  2. Point it at your domain

    It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.

  3. Read the report, then schedule it

    Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.

On-premises, and read-only

An auditing tool that ships your directory contents somewhere else is a strange way to improve your security posture.

  • Runs entirely on hardware you control — there is no Secure90 cloud service to sign up for.
  • No directory data, account names, or report contents are transmitted to Secure90.
  • Read-only by design: the tool never writes to, disables, or deletes an object in your directory.
  • No agents and no schema extensions on domain controllers.
  • Works in air-gapped and disconnected environments.

Handed one of these jobs?

From the blog

All posts →

Get On-Prem AD Auditor

Free, forever. No license keys, no per-user pricing, no seat counts, no trial timer.