Animated clock branching to three AD objects, each lighting up in sequence with a pencil change badge as its history is read

Active Directory Change Auditor

See who changed what in Active Directory, and when - account lifecycle events, group membership changes, and Directory Service Changes with the real old and new attribute value, read straight from your domain controllers' own Security event log.

Active Directory Info and Active Directory Permission Reporter both answer "what does the directory look like right now" - a point-in-time snapshot. Active Directory Change Auditor answers the question neither of them can: who added that account to Domain Admins, and when? It reads the Security event log on every reachable domain controller for a well-known set of audit events - account created/enabled/disabled/deleted, admin password resets, group membership added/removed (including a dedicated view for privileged groups like Domain Admins, Enterprise Admins, Schema Admins, and Administrators), and Directory Service Changes events that carry the actual old and new attribute value, not just which field changed. Every event - regardless of type - lands in one unified list with 22 built-in queries: time-windowed views (last 24 hours/7 days/30 days), lifecycle filters, privileged-group-membership changes, and parameterized searches for a specified actor or attribute name. Build your own queries with custom filter conditions, export to CSV, Excel, HTML, XML, or the clipboard, and schedule any of it to run - and email itself to you - unattended.

Screenshot

See it in action

The real app. Click to zoom in, hover the markers to see what each part does.

Active Directory Change Auditor showing the unified query list with a small clock icon next to every built-in query, the 'All changes' query selected, and its results grid populated with 13 change events showing Timestamp, Event ID, Change Type, and Actor Name
Click to zoom

Hover a marker for details, or click the screenshot to zoom in.

Active Directory Change Auditor, zoomed in
Features

Every change, who made it, explained

Real actor and timestamp attribution

Reads the Security event log directly, so every row shows who actually made the change and exactly when - not just that something differs since the last scan.

22 built-in queries, one unified list

Time-windowed views, account lifecycle events, group membership added/removed, privileged-group-membership changes, admin password resets, and Directory Service Changes filters - no separate tab per event type, since every change shares the same auditable-fact shape.

Real old and new attribute values

Directory Service Changes events (when enabled on your DCs) carry the actual before/after value of the attribute that changed - not just its name.

Privileged group membership, front and center

A dedicated built-in query surfaces every membership change to Domain Admins, Enterprise Admins, Schema Admins, and Administrators - the changes that matter most, without having to build a filter yourself.

Custom queries & attributes

Build your own query from filter conditions on any attribute, register extra attributes under a friendly display name via Manage Custom Attributes, and search by specified actor or attribute name.

Scheduled & emailed reports

Save any query as a recurring report via Windows Task Scheduler, with the result optionally emailed to you afterward - or drive it yourself from scripts with ActiveDirectoryChangeAuditor.exe --run-report ... and --run-query ....

Plans & Pricing

Each tier unlocks more

Pick how much automation you need, then choose once-off or monthly billing. Active Directory Change Auditor licenses per machine, not by domain size.

One-time payment - yours to keep, no subscription.

Standard

For core account auditing.

Account lifecycle auditing (created/enabled/disabled/deleted, password resets) and time-windowed queries, on screen, free at every tier.

Standard+

For the complete membership picture.

Everything in Standard, plus group membership added/removed events and CSV/Text export.

Advanced

For deeper investigation.

Everything in Standard+, plus custom queries, privileged-group-membership queries, richer export formats, and actor search.

All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.

Standard

Standard covers the core of any account audit: user and computer lifecycle events (created, enabled, disabled, deleted, password reset), the full time-windowed query catalog, and column selection - all on screen. No group membership events or export at this tier, by design.

Best for: Anyone who needs a fast answer to "when was this account disabled, and by whom?"

Standard+

Standard+ adds group membership added/removed events - including the privileged-group query - plus CSV/Text report export. Everything from Standard is included.

Best for: Day-to-day monitoring of who's being added to sensitive groups.

Advanced

Advanced adds custom queries with Manage Custom Attributes, Excel/HTML/XML/clipboard export, and the "changes by specified actor" search. Everything from Standard+ is included.

Best for: Security teams building their own change-review reports or investigating a specific admin's activity.

Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.

Interested in Active Directory Change Auditor?

Contact us for current pricing and licensing options.

Contact us