For teams preparing evidence for an audit or access review

User Access Reviews and Audit Evidence from Active Directory

A user access review asks a simple question that is tedious to answer: who has access to what, is it still appropriate, and can you prove somebody checked? Most teams answer it with a spreadsheet export, a round of emails to managers, and a fortnight of chasing — repeated every quarter, from scratch.

What auditors usually ask for

A complete account inventory
Every account, its status, when it was last used, and who owns it. Completeness is the point — a list that omits service accounts invites the next question.
Privileged access, itemized
Who holds administrative rights, how they got them (directly or through nesting), and when the membership was granted.
Evidence that leavers were removed
Not just that the account is disabled today, but that it was disabled promptly — which needs a record from more than one point in time.
Proof the review actually happened
A dated artefact produced on a schedule, not a spreadsheet with a modified date of last Thursday.

Turning that into a repeatable process

The reports below are the evidence pack. Scheduling them is what turns a quarterly scramble into an existing artefact you already have when the request arrives.

  1. Generate the account inventory

    Enabled, disabled, and stale accounts across every domain in the forest, with OU and last-use context attached so a manager can actually review their own list.

  2. Attach the privileged-access report

    Recursive membership of every privileged group, with the nesting path — the difference between "eleven Domain Admins" and "eleven Domain Admins, six of them via a nested group nobody reviewed".

  3. Schedule both, monthly or quarterly

    Delivered by email to the reviewers on a fixed date. The schedule itself becomes part of the evidence: the review is a process, not an event.

  4. Keep the run history

    Each run is retained, so the delta between reviews shows what was remediated and when — which is the question that follows every finding.

What you end up with

  • A dated, repeatable evidence pack rather than an ad-hoc export
  • Per-manager account lists that can be reviewed without IT translating them first
  • A demonstrable remediation trail between review cycles
  • The same reports available on demand when an auditor asks mid-cycle

Frequently asked questions

Can managers review their own team without an AD console?
Yes — the exported reports are the point. A CSV or PDF scoped to an OU can go to the person who owns that part of the business without giving them directory access.
Does this satisfy ISO 27001 or SOC 2?
No tool satisfies a control on its own. This produces the directory-side evidence — account inventory, privileged access, and a dated review history — that access-review controls typically require you to show. The mapping is between you and your auditor.
How far back does the history go?
As far back as you have been running it. Every scheduled run is retained locally, which is why starting the schedule before you need the evidence matters more than the first report does.

Get SysFlint AD

Free, forever. No license keys, no per-user pricing, no seat counts, no trial timer.