Animated shield branching to three AD objects, each lighting up in sequence with a padlock badge as its permissions are read

Active Directory Permission Reporter

See exactly who has what rights on every Active Directory object - Users, Groups, Computers, Containers & OUs, and Group Policy Objects - one row per access control entry, with the trustee, Allow or Deny, the rights granted, and whether it's inherited or explicit.

Active Directory Permission Reporter reads the actual security descriptor (nTSecurityDescriptor) on every object it scans and turns each access control entry into one report row - who the trustee is, whether the entry is Allow or Deny, which rights it grants, whether it's inherited from a parent container or explicit on the object itself, and (where relevant) which specific property or extended right it's scoped to, like "Reset Password". Every object type - Users, Groups, Computers, Containers & OUs, and Group Policy Objects - shows up in one unified list with 26 built-in queries, since the underlying ACE model is identical no matter which object class it's attached to: explicit vs inherited, Allow vs Deny, grants to Everyone or Authenticated Users, orphaned/unresolvable SIDs, "On ... objects only" filters, and parameterized searches for a specified trustee or right. Build your own queries with custom filter conditions, export to CSV, Excel, HTML, XML, or the clipboard, and schedule any of it to run - and email itself to you - unattended.

Screenshot

See it in action

The real app. Click to zoom in, hover the markers to see what each part does.

Active Directory Permission Reporter showing the unified query list with a small icon next to every built-in query, the 'All permissions' query selected, and its results grid populated with 27 permission entries spanning every object type, with Object Type as one of the result columns
Click to zoom

Hover a marker for details, or click the screenshot to zoom in.

Active Directory Permission Reporter, zoomed in
Features

Every ACE, on every object, explained

One row per access control entry

Every ACE on an object's security descriptor becomes a report row: trustee, Allow/Deny, rights granted, inherited or explicit, and what it applies to - not just a summary, the actual ACL.

26 built-in queries, one unified list

Explicit vs inherited permissions, Allow vs Deny, Full Control grants, grants to Everyone or Authenticated Users, orphaned/unresolvable SIDs, trustee account type, property/extended-right-scoped entries like "Reset Password", and "On ... objects only" filters - no separate tab per object type needed, since the ACE model is shared.

Scope and column control

Every query run lets you search the entire domain or limit it to one OU (with or without sub-containers), and pick exactly which attributes come back - the same "Select Output Attributes and Container" step whether it's a built-in query or your own.

Custom queries & attributes

Build your own query from filter conditions on any attribute, register extra attributes under a friendly display name via Manage Custom Attributes, and reuse them alongside the built-in catalog - filterable to "custom queries only".

Export anywhere

CSV, Excel (a real .xlsx, no Office install required), HTML, XML, plain text, or straight to the clipboard - one shared export path for every query, built-in or custom.

Scheduled & emailed reports

Save any query as a recurring report via Windows Task Scheduler, with the result optionally emailed to you afterward - or drive it yourself from scripts with ActiveDirectoryPermissionReporter.exe --run-report ... and --run-query ....

Plans & Pricing

Each tier unlocks more

Pick how much automation you need, then choose once-off or monthly billing. Active Directory Permission Reporter licenses per machine, not by domain size.

One-time payment - yours to keep, no subscription.

Standard

For core permission audits.

Full permission reporting on Users, Groups, and Computers, on screen, free at every tier.

Standard+

For the complete object picture.

Everything in Standard, plus Containers & OUs / Group Policy Objects reporting and CSV/Text export.

Advanced

For deeper investigation.

Everything in Standard+, plus custom queries, richer export formats, and the effective-permissions search for a specified trustee.

All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.

Standard

Standard covers the core of any permission audit: full ACE-level reporting on Users, Groups, and Computers, with the complete built-in query catalog, scoped search, and column selection - all on screen. No Containers & OUs/GPO reporting or export at this tier, by design.

Best for: Anyone who needs a fast answer to "who has access to this account or group?"

Standard+

Standard+ adds the two remaining report categories - Containers & OUs and Group Policy Objects - plus CSV/Text report export. Everything from Standard is included.

Best for: Day-to-day delegation reviews across the whole directory, not just accounts.

Advanced

Advanced adds custom queries with Manage Custom Attributes, Excel/HTML/XML/clipboard export, and the cross-category effective-permissions search for a specified trustee. Everything from Standard+ is included.

Best for: Security teams building their own delegation or excessive-access reports.

Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.

Interested in Active Directory Permission Reporter?

Contact us for current pricing and licensing options.

Contact us