See who changed what in Active Directory, and when - account lifecycle events, group membership changes, and Directory Service Changes with the real old and new attribute value, read straight from your domain controllers' own Security event log.
Active Directory Info and Active Directory Permission Reporter both answer "what does the directory look like right now" - a point-in-time snapshot. Active Directory Change Auditor answers the question neither of them can: who added that account to Domain Admins, and when? It reads the Security event log on every reachable domain controller for a well-known set of audit events - account created/enabled/disabled/deleted, admin password resets, group membership added/removed (including a dedicated view for privileged groups like Domain Admins, Enterprise Admins, Schema Admins, and Administrators), and Directory Service Changes events that carry the actual old and new attribute value, not just which field changed. Every event - regardless of type - lands in one unified list with 22 built-in queries: time-windowed views (last 24 hours/7 days/30 days), lifecycle filters, privileged-group-membership changes, and parameterized searches for a specified actor or attribute name. Build your own queries with custom filter conditions, export to CSV, Excel, HTML, XML, or the clipboard, and schedule any of it to run - and email itself to you - unattended.
The real app. Click to zoom in, hover the markers to see what each part does.
Hover a marker for details, or click the screenshot to zoom in.
Reads the Security event log directly, so every row shows who actually made the change and exactly when - not just that something differs since the last scan.
Time-windowed views, account lifecycle events, group membership added/removed, privileged-group-membership changes, admin password resets, and Directory Service Changes filters - no separate tab per event type, since every change shares the same auditable-fact shape.
Directory Service Changes events (when enabled on your DCs) carry the actual before/after value of the attribute that changed - not just its name.
A dedicated built-in query surfaces every membership change to Domain Admins, Enterprise Admins, Schema Admins, and Administrators - the changes that matter most, without having to build a filter yourself.
Build your own query from filter conditions on any attribute, register extra attributes under a friendly display name via Manage Custom Attributes, and search by specified actor or attribute name.
Save any query as a recurring report via Windows Task Scheduler, with the result optionally emailed to you afterward - or drive it yourself from scripts with ActiveDirectoryChangeAuditor.exe --run-report ... and --run-query ....
Pick how much automation you need, then choose once-off or monthly billing. Active Directory Change Auditor licenses per machine, not by domain size.
One-time payment - yours to keep, no subscription.
For core account auditing.
Account lifecycle auditing (created/enabled/disabled/deleted, password resets) and time-windowed queries, on screen, free at every tier.
For the complete membership picture.
Everything in Standard, plus group membership added/removed events and CSV/Text export.
For deeper investigation.
Everything in Standard+, plus custom queries, privileged-group-membership queries, richer export formats, and actor search.
For fully unattended audits.
Everything in Advanced, plus scheduled & emailed reports and a headless CLI.
All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.
Standard covers the core of any account audit: user and computer lifecycle events (created, enabled, disabled, deleted, password reset), the full time-windowed query catalog, and column selection - all on screen. No group membership events or export at this tier, by design.
Best for: Anyone who needs a fast answer to "when was this account disabled, and by whom?"
Standard+ adds group membership added/removed events - including the privileged-group query - plus CSV/Text report export. Everything from Standard is included.
Best for: Day-to-day monitoring of who's being added to sensitive groups.
Advanced adds custom queries with Manage Custom Attributes, Excel/HTML/XML/clipboard export, and the "changes by specified actor" search. Everything from Standard+ is included.
Best for: Security teams building their own change-review reports or investigating a specific admin's activity.
Professional adds scheduled reports via Windows Task Scheduler with optional email delivery, and a headless CLI (ActiveDirectoryChangeAuditor.exe --run-report, --run-query, --run-custom-query). Everything from Advanced is included.
Best for: Organizations that want recurring change audits - and alerts on privileged-group changes - running themselves.
Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.
Contact us for current pricing and licensing options.
Contact us