Free, forever
SysFlint AD
SysFlint AD finds the disabled, stale, and over-privileged accounts hiding in your Active Directory, turns them into audit-ready reports, and emails those reports on a schedule. It runs entirely inside your network — no cloud account, no agents on your domain controllers, no directory data leaving your environment.
Every AD estate accumulates accounts nobody owns
Leavers who were disabled but never removed. Contractors whose accounts still sit in a privileged group. Service accounts with passwords set never to expire, created by someone who left three years ago. None of it shows up until an audit, an incident, or an insurer asks — and by then you are reconstructing history from a spreadsheet.
- The answers exist in AD, but only as a PowerShell script somebody has to remember to run.
- A CSV export is a snapshot — it cannot tell you whether the problem is getting better or worse.
- Getting the report to security, IT ops, and audit on a schedule means building that plumbing yourself.
- Commercial AD auditing suites solve it, at a license cost that is hard to justify for a monthly report.
How it works
Install on a domain-joined machine
One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.
Point it at your domain
It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.
Read the report, then schedule it
Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.
What it reports on
Each report has its own page covering how the job is usually done by hand and where that runs out of road.
Disabled account reports
Every disabled account, with the OU it lives in, when it was last used, and how long it has been sitting there.
Learn more →Stale and inactive account detection
Enabled accounts that nobody has logged into for 30, 60, or 90+ days — the ones that are still a live attack surface.
Learn more →Privileged group auditing
Who is in Domain Admins, Enterprise Admins, and Schema Admins — including nested membership and accounts that should not be there.
Learn more →Password and expiry reporting
Accounts with "password never expires", passwords older than your policy, and accounts that never set one at all.
Learn more →Scheduled reports by email
Daily, weekly, or monthly runs delivered to the right inbox automatically. No Task Scheduler job for you to babysit.
Learn more →Multi-domain and forest coverage
Enumerate every domain in the forest in one pass and get one consolidated report instead of one per domain.
Learn more →
On-premises means on-premises
An auditing tool that ships your directory contents to someone else's infrastructure is a strange way to improve your security posture.
- Runs entirely on hardware you control — there is no SysFlint cloud service to sign up for.
- No directory data, account names, or report contents are transmitted to SysFlint.
- Read-only by design: the tool never writes to, disables, or deletes an object in your directory.
- No agents and no schema extensions on domain controllers.
- Works in air-gapped and disconnected environments.
Requirements
- Operating system
- Windows Server 2016+ or Windows 10/11 (amd64)
- Directory
- Active Directory Domain Services (any functional level 2008 R2+)
- Permissions
- A read-only domain account — no Domain Admin rights required
- Network
- LDAP/LDAPS reachability to at least one domain controller
- Domain controllers
- No agent, no software, and no schema change on any DC
- Internet access
- Not required — the tool runs fully offline
Confirm the exact requirements against the version you download — they can shift slightly release to release.
Where it fits
Jobs it is built for
Frequently asked questions
- Is SysFlint AD really free?
- Yes — free forever, with no license key, no per-user or per-object pricing, and no trial that expires. Read more on the pricing page.
- Does it install anything on my domain controllers?
- No. It installs on a single domain-joined machine of your choosing and reads the directory over standard LDAP/LDAPS. Nothing is deployed to a domain controller and the AD schema is never modified.
- Does any of my Active Directory data leave my network?
- No. There is no cloud component and no telemetry containing directory data. Everything the tool reads, stores, and reports on stays on the machine you installed it on.
- What permissions does it need?
- A standard read-only domain account is enough for the core reports. Domain Admin rights are not required, and the tool never asks for write access to the directory.
- Will it change anything in my directory?
- No. It is strictly read-only. It reports on disabled, stale, and over-privileged accounts; acting on them stays a deliberate decision you make in your usual tooling.
- When is it available?
- Now. The Windows installer is on the download page, with its version and SHA-256 checksum, along with an archive of every earlier release.
Get SysFlint AD
Free, forever. No license keys, no per-user pricing, no seat counts, no trial timer.