Free — read-only
SysFlint AD
SysFlint AD finds the disabled, stale, and over-privileged accounts hiding in your Active Directory and turns them into audit-ready reports — every report, every dashboard, unlimited domains, free forever, no read access held back. It runs entirely inside your network — no cloud account, no agents on your domain controllers, no directory data leaving your environment. Two things need a free evaluation key: running those reports unattended on a schedule, and writing a snapshot back to AD.
Every AD estate accumulates accounts nobody owns
Leavers who were disabled but never removed. Contractors whose accounts still sit in a privileged group. Service accounts with passwords set never to expire, created by someone who left three years ago. None of it shows up until an audit, an incident, or an insurer asks — and by then you are reconstructing history from a spreadsheet.
- The answers exist in AD, but only as a PowerShell script somebody has to remember to run.
- A CSV export is a snapshot — it cannot tell you whether the problem is getting better or worse.
- Getting the report to security, IT ops, and audit on a schedule means building that plumbing yourself.
- Commercial AD auditing suites solve it, at a license cost that is hard to justify for a monthly report.
How it works
Install on a domain-joined machine
One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.
Point it at your domain
It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.
Read the report, then schedule it
Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.
What it reports on
Each report has its own page covering how the job is usually done by hand and where that runs out of road.
Disabled account reports
Every disabled account, with the OU it lives in, when it was last used, and how long it has been sitting there.
Learn more →Stale and inactive account detection
Enabled accounts that nobody has logged into for 30, 60, or 90+ days — the ones that are still a live attack surface.
Learn more →Privileged group auditing
Who is in Domain Admins, Enterprise Admins, and Schema Admins — including nested membership and accounts that should not be there.
Learn more →Password and expiry reporting
Accounts with "password never expires", passwords older than your policy, and accounts that never set one at all.
Learn more →Scheduled reports by email
Daily, weekly, or monthly runs delivered to the right inbox automatically. No Task Scheduler job for you to babysit.
Learn more →Multi-domain and forest coverage
Enumerate every domain in the forest in one pass and get one consolidated report instead of one per domain.
Learn more →
On-premises means on-premises
An auditing tool that ships your directory contents to someone else's infrastructure is a strange way to improve your security posture.
- Runs entirely on hardware you control — there is no SysFlint cloud service to sign up for.
- No directory data, account names, or report contents are transmitted to SysFlint.
- Read-only for every report and every diff: nothing is written to your directory just by looking at one. The one exception is deliberate — restoring a snapshot back to AD — and it only ever runs on changes you explicitly select and confirm, never automatically.
- No agents and no schema extensions on domain controllers.
- Works in air-gapped and disconnected environments.
Requirements
- Operating system
- Windows Server 2016+ or Windows 10/11 (amd64)
- Directory
- Active Directory Domain Services (any functional level 2008 R2+)
- Permissions
- A read-only domain account for reporting — no Domain Admin rights required. Applying a diff back to AD (a separate, licensed, opt-in action) needs a write-capable account instead.
- Network
- LDAP/LDAPS reachability to at least one domain controller
- Domain controllers
- No agent, no software, and no schema change on any DC
- Internet access
- Not required — the tool runs fully offline
Confirm the exact requirements against the version you download — they can shift slightly release to release.
Where it fits
Frequently asked questions
- Is SysFlint AD really free?
- Yes — every report, every domain, on-demand exports, and viewing any diff are free forever, with no per-user or per-object pricing. A free evaluation key is only needed for two things: running exports on a schedule, and applying a diff back to AD. Read more on the pricing page.
- Does it install anything on my domain controllers?
- No. It installs on a single domain-joined machine of your choosing and reads the directory over standard LDAP/LDAPS. Nothing is deployed to a domain controller and the AD schema is never modified.
- Does any of my Active Directory data leave my network?
- No. There is no cloud component and no telemetry containing directory data. Everything the tool reads, stores, and reports on stays on the machine you installed it on.
- What permissions does it need?
- A standard read-only domain account is enough for the core reports. Domain Admin rights are not required, and the tool never asks for write access to the directory.
- Will it change anything in my directory?
- No. It is strictly read-only. It reports on disabled, stale, and over-privileged accounts; acting on them stays a deliberate decision you make in your usual tooling.
- When is it available?
- Now. The Windows installer is on the download page, with its version and SHA-256 checksum, along with an archive of every earlier release.
Get SysFlint AD
Free — read-only. No per-user pricing, no seat counts, no trial timer for reporting. A free evaluation key unlocks two things: scheduled exports and writing a diff back to AD — see the pricing page.