- Published on
Free, forever · On-premises · No agents on your DCs
Find the accounts your Active Directory forgot about.
On-Prem AD Auditor reports on the disabled, stale, and over-privileged accounts sitting in your domain — and emails those reports on a schedule. It runs entirely inside your own network, and it costs nothing.
What it reports on
Six reports covering the questions an auditor, an insurer, or a pentest report is most likely to ask first.
Disabled account reports
Every disabled account, with the OU it lives in, when it was last used, and how long it has been sitting there.
Learn more →Stale and inactive account detection
Enabled accounts that nobody has logged into for 30, 60, or 90+ days — the ones that are still a live attack surface.
Learn more →Privileged group auditing
Who is in Domain Admins, Enterprise Admins, and Schema Admins — including nested membership and accounts that should not be there.
Learn more →Password and expiry reporting
Accounts with "password never expires", passwords older than your policy, and accounts that never set one at all.
Learn more →Scheduled reports by email
Daily, weekly, or monthly runs delivered to the right inbox automatically. No Task Scheduler job for you to babysit.
Learn more →Multi-domain and forest coverage
Enumerate every domain in the forest in one pass and get one consolidated report instead of one per domain.
Learn more →
How it works
Install on a domain-joined machine
One installer on any domain-joined Windows machine — a management server, a jump box, or your own workstation. Nothing is installed on your domain controllers and the AD schema is never modified.
Point it at your domain
It reads the directory over standard LDAP/LDAPS using a read-only account. No write permissions are needed or requested. Multi-domain forests are enumerated in a single pass.
Read the report, then schedule it
Get an audit-ready report immediately, export it to CSV or PDF, then set it to run daily, weekly, or monthly and email itself to the people who need it. Each run is kept, so you can see trends instead of one-off snapshots.
On-premises, and read-only
An auditing tool that ships your directory contents somewhere else is a strange way to improve your security posture.
- Runs entirely on hardware you control — there is no Secure90 cloud service to sign up for.
- No directory data, account names, or report contents are transmitted to Secure90.
- Read-only by design: the tool never writes to, disables, or deletes an object in your directory.
- No agents and no schema extensions on domain controllers.
- Works in air-gapped and disconnected environments.
Handed one of these jobs?
Use cases
Weighing it against something else
From the blog
All posts →- LastLogonDate can be up to two weeks stale. This PowerShell script queries the non-replicated LastLogon attribute on every domain controller directly and returns the real answer.
- Published on
A PowerShell script to list deleted Active Directory user accounts still sitting in the AD Recycle Bin — plus how to check whether the Recycle Bin is even enabled, and how to actually restore what you find.- Published on
A PowerShell script that resolves a user's complete Active Directory group membership, including groups they only belong to through nested membership — the thing MemberOf alone can't tell you.
Get On-Prem AD Auditor
Free, forever. No license keys, no per-user pricing, no seat counts, no trial timer.