Stale Account Detection
Find dormant logins and stale passwords across every OU. Configurable thresholds, OU-level exclusions, and per-user overrides.
Identify stale accounts, privilege creep, password-policy violations, HR Census mismatches, and AD risks — before they become security incidents.
Every check is configurable, every result is exportable, every flag is one click away from a remediation decision.
Find dormant logins and stale passwords across every OU. Configurable thresholds, OU-level exclusions, and per-user overrides.
Membership of Domain Admins, Enterprise Admins, and any custom group you flag — directly or through Primary Group ID.
Compare AD against your HR roster by name, email, title, department, company, or manager. Aliases handle real-world data drift.
Filter results, then export to .txt, .csv, or .pdf for ticketing, audit prep, or compliance evidence. Nothing leaves your network.
Flag accounts with password-never-expires, no password required, empty passwords, or reversible encryption enabled.
Surface enabled accounts missing a title, manager, department, company, or description — and contractor accounts past their expiry.
Find empty security and distribution groups, Kerberoastable SPNs, unconstrained delegation, and stale AdminSDHolder accounts.
Runs entirely on your workstation against your own DC. No agent to deploy, no telemetry, no cloud upload — your AD data stays put.
"We replaced three half-finished PowerShell scripts with AD Auditor. The HR reconciliation alone paid for it in the first month."
"The lockout investigation and stale account checks are exactly what an MSP team needs. Clean UI, no fluff, fully offline."
"Privileged group review used to take a day across our domains. With AD Auditor it's two clicks and an export."
One-time purchase or yearly subscription. No per-seat fees. No telemetry. No vendor lock-in.
Per administrator, billed yearly. Includes all updates within the year.
One-time purchase. Use forever on the current major version. No subscription.