Hybrid estates generate activity across directories, Windows systems, file servers and cloud services. Reviewing changes, sign-ins, access events and authentication failures requires records that link activity to the relevant system and time.
ADAudit Plus collects audit events across these areas and presents them through reports and alerts. It tracks identity and file activity, records Windows system events, identifies account lockout sources, and detects specified attacks, anomalous behaviour and risky cloud configurations.
ADAudit Plus is suited to reviewing Active Directory and Microsoft Entra ID changes and sign-ins, investigating account lockouts, and examining file access, ownership and permission changes on Windows and NAS file servers. It also supports review of Windows Server and workstation activity, scheduled audit reporting, and alerts for critical or suspicious activity.
ADAudit Plus applies to hybrid environments using Active Directory, Microsoft Entra ID, Windows servers and workstations, Windows or NAS file servers, and Azure, AWS or GCP. AD Backup and Recovery and File Analysis sit outside the product's core auditing, reporting, alerting and specified detection functions.
Provides records for reviewing significant identity, Windows, file and cloud events.
Identifying authentication failure sources gives teams context for investigating account lockouts.
Email and SMS alerts bring critical activity and suspicious thresholds to attention.
Scheduled report delivery makes collected audit data available for routine review.
Review Active Directory and Microsoft Entra ID changes and sign-in activity.
Investigate access, changes, ownership and permission events on supported file servers.
Trace the source of authentication failures associated with account lockouts.
Identify risky configurations in supported Azure, AWS and GCP environments.
Schedule delivery of audit reports generated from collected event data.