ADAudit Plus

Audits activity and changes across hybrid identity, Windows, file and cloud environments.

For hybrid estates requiring audit records and alerts across directory, Windows, file and cloud activity.

Audit hybrid identity, Windows and file activity

Hybrid estates generate activity across directories, Windows systems, file servers and cloud services. Reviewing changes, sign-ins, access events and authentication failures requires records that link activity to the relevant system and time.

ADAudit Plus collects audit events across these areas and presents them through reports and alerts. It tracks identity and file activity, records Windows system events, identifies account lockout sources, and detects specified attacks, anomalous behaviour and risky cloud configurations.

Where ADAudit Plus is used

ADAudit Plus is suited to reviewing Active Directory and Microsoft Entra ID changes and sign-ins, investigating account lockouts, and examining file access, ownership and permission changes on Windows and NAS file servers. It also supports review of Windows Server and workstation activity, scheduled audit reporting, and alerts for critical or suspicious activity.

Fits within these solutions

Active Directory Reporting
File Activity Monitoring
Compliance Reporting
Microsoft 365 Reporting
Exchange Reporting
SharePoint & OneDrive Reporting

Suitable environments

ADAudit Plus applies to hybrid environments using Active Directory, Microsoft Entra ID, Windows servers and workstations, Windows or NAS file servers, and Azure, AWS or GCP. AD Backup and Recovery and File Analysis sit outside the product's core auditing, reporting, alerting and specified detection functions.

Benefits

Reviewable Activity Records

Provides records for reviewing significant identity, Windows, file and cloud events.

Lockout Investigation Context

Identifying authentication failure sources gives teams context for investigating account lockouts.

Critical Activity Notification

Email and SMS alerts bring critical activity and suspicious thresholds to attention.

Scheduled Audit Reporting

Scheduled report delivery makes collected audit data available for routine review.

Capabilities

Directory Activity Auditing

Tracks changes and sign-ins in Active Directory and Microsoft Entra ID.

File Server Auditing

Audits file access, changes, ownership changes and permission changes on Windows and NAS file servers.

Windows Activity Records

Records Windows Server and workstation logons, system events, account activity and file integrity events.

Account Lockout Analysis

Alerts on account lockouts and identifies the source of authentication failures.

Specified Threat Detection

Detects specified Active Directory attacks, anomalous user behaviour and risky cloud configurations.

Reports and Alerts

Generates scheduled audit reports and sends email or SMS alerts for critical activity.

Common Use Cases

Directory Change Review

Review Active Directory and Microsoft Entra ID changes and sign-in activity.

File Access Investigation

Investigate access, changes, ownership and permission events on supported file servers.

Account Lockout Investigation

Trace the source of authentication failures associated with account lockouts.

Cloud Configuration Review

Identify risky configurations in supported Azure, AWS and GCP environments.

Routine Audit Reporting

Schedule delivery of audit reports generated from collected event data.

Part of (depending on licence)

Resources

How would you like to proceed?