Skip to content

Security audit

Use Security → Audit (/security/audit) to review privileged users and groups, service principal names (SPNs), and accounts missing contact or ownership information. A finding is a lead for investigation, not an automatic vulnerability verdict. Confirm business purpose and applicable policy before changing an account.

Dashboard → Domain (/domain/info) includes domain health checks for LDAP, domain controllers, DNS, SYSVOL/NETLOGON reachability, time drift and LDAP certificate expiry. Refresh the checks to obtain a new snapshot, then open the details for failing checks. Network permissions and controller configuration affect what can be measured.

Directory audit (/domain/audit) lets you filter object changes by name, DN, action and period. Application change journal entries include the operator, time and before/after data for actions made through the application; sensitive credential fields are redacted. This journal is not a replacement for native AD auditing.