Free, forever

SysFlint AD

SysFlint AD finds the disabled, stale, and over-privileged accounts hiding in your Active Directory, turns them into audit-ready reports, and emails those reports on a schedule. It runs entirely inside your network — no cloud account, no agents on your domain controllers, no directory data leaving your environment.

Every AD estate accumulates accounts nobody owns

Leavers who were disabled but never removed. Contractors whose accounts still sit in a privileged group. Service accounts with passwords set never to expire, created by someone who left three years ago. None of it shows up until an audit, an incident, or an insurer asks — and by then you are reconstructing history from a spreadsheet.

  • The answers exist in AD, but only as a PowerShell script somebody has to remember to run.
  • A CSV export is a snapshot — it cannot tell you whether the problem is getting better or worse.
  • Getting the report to security, IT ops, and audit on a schedule means building that plumbing yourself.
  • Commercial AD auditing suites solve it, at a license cost that is hard to justify for a monthly report.

How it works

  1. Install on a domain-joined machine

    One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.

  2. Point it at your domain

    It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.

  3. Read the report, then schedule it

    Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.

What it reports on

Each report has its own page covering how the job is usually done by hand and where that runs out of road.

On-premises means on-premises

An auditing tool that ships your directory contents to someone else's infrastructure is a strange way to improve your security posture.

  • Runs entirely on hardware you control — there is no SysFlint cloud service to sign up for.
  • No directory data, account names, or report contents are transmitted to SysFlint.
  • Read-only by design: the tool never writes to, disables, or deletes an object in your directory.
  • No agents and no schema extensions on domain controllers.
  • Works in air-gapped and disconnected environments.

Requirements

Operating system
Windows Server 2016+ or Windows 10/11 (amd64)
Directory
Active Directory Domain Services (any functional level 2008 R2+)
Permissions
A read-only domain account — no Domain Admin rights required
Network
LDAP/LDAPS reachability to at least one domain controller
Domain controllers
No agent, no software, and no schema change on any DC
Internet access
Not required — the tool runs fully offline

Confirm the exact requirements against the version you download — they can shift slightly release to release.

Where it fits

Frequently asked questions

Is SysFlint AD really free?
Yes — free forever, with no license key, no per-user or per-object pricing, and no trial that expires. Read more on the pricing page.
Does it install anything on my domain controllers?
No. It installs on a single domain-joined machine of your choosing and reads the directory over standard LDAP/LDAPS. Nothing is deployed to a domain controller and the AD schema is never modified.
Does any of my Active Directory data leave my network?
No. There is no cloud component and no telemetry containing directory data. Everything the tool reads, stores, and reports on stays on the machine you installed it on.
What permissions does it need?
A standard read-only domain account is enough for the core reports. Domain Admin rights are not required, and the tool never asks for write access to the directory.
Will it change anything in my directory?
No. It is strictly read-only. It reports on disabled, stale, and over-privileged accounts; acting on them stays a deliberate decision you make in your usual tooling.
When is it available?
Now. The Windows installer is on the download page, with its version and SHA-256 checksum, along with an archive of every earlier release.

Get SysFlint AD

Free, forever. No license keys, no per-user pricing, no seat counts, no trial timer.