Home > Products > Gold Finger > Reports
Gold Finger -

List of Reports
The following is a comprehensive list of over 200 Active Directory reports available in the Gold Finger Suite -
Note - Please click on a specific category above to view its list of reports.
The reports in categories 1 to 4 are unique to Gold Finger, in that only Gold Finger can accurately generate them. They are very difficult to accurately generate, and reports 2 to 4 are powered by our patented access assessment technology.
The reports in categories 5 to 8 are exponentially easier to generate, and thus also available in various other tools, and in these categories, Gold Finger offers these reports to provide a professional-grade, trustworthy alternative to other tools.
1. Reports available in Active Directory Effective Permissions Calculator
Who has what effective permissions on an Active Directory object?
2. Reports available in Active Directory Effective Access Auditor
Who has what effective access on an Active Directory object?
3. Reports available in Active Directory Privilege Escalation Path Identifier
Identify all security principals that have a privilege escalation path to an Active Directory object
Identify all privilege escalation paths leading to an Active Directory object
Identify all privilege escalation paths leading to multiple objects in an Active Directory tree
4. Reports available in Active Directory Privileged Access Assessor
Who can create user accounts?
Who can delete user accounts?
Who can reset user account passwords?
Who can disable/enable user accounts?
Who can unlock locked user accounts?
Who can change the expiration date of user accounts?
Who can disable/enable smartcard requirement for interactive logon by user accounts?
Who can force users to change their user account passwords at next logon?
Who can prevent users from changing their user account passwords?
Who can change the logon name of user accounts?
Who can change the Pre-Windows 2000 logon name of user accounts?
Who can change the logon hours of user accounts?
Who can change the logon workstations of user accounts?
Who can change the profile path for user accounts?
Who can change the logon script for user accounts?
Who can change alternate security identities associated with user accounts?
Who can change whether or not user accounts are sensitive and cannot be delegated?
Who can change whether or not DES encryption types should be used for user accounts?
Who can change whether or not Kerberos pre-authentication is required for user accounts?
Who can change the first name of user accounts?
Who can change the last name of user accounts?
Who can change the display name of user accounts?
Who can change the organizational title of user accounts?
Who can change the security permissions protecting user accounts?
Who can change the owner of user accounts?
Who can create computer accounts?
Who can delete computer accounts?
Who can reset computer accounts?
Who can disable/enable computer accounts?
Who can change the expiration date of computer accounts?
Who can change the computer name (Pre-Windows 2000) of computer accounts?
Who can change the DNS name of computer accounts?
Who can change the machine role of computer accounts?
Who can change the description of computer accounts?
Who can change the Service Principal Names (SPNs) of computer accounts?
Who can change alternate security identities associated with computer accounts?
Who can change the security permissions protecting computer accounts?
Who can change the owner of computer accounts?
Who can create security groups?
Who can delete security groups?
Who can change security group memberships?
Who can add/remove onself to/from the membership of security groups?
Who can change security group scopes?
Who can change security group types?
Who can change the group name (Pre-Windows 2000) of security groups?
Who can change the description of security groups?
Who can change the email-address of security groups?
Who can change the notes annotated for security groups?
Who can change the designated manager of security groups?
Who can change the security permissions protecting security groups?
Who can change the owner of security groups?
Who can change the maximum password age for domain user accounts?
Who can change the minimum password age for domain user accounts?
Who can change the lockout duration for domain user accounts?
Who can change the lockout threshold for domain user accounts?
Who can change the lockout observation window for domain user accounts?
Who can create organizational units?
Who can delete organizational units?
Who can disable group policies linked to organizational units?
Who can change the list of group policies linked to organizational units?
Who can change the precedence of group policies linked to organizational units?
Who can generate resultant set of policy (logging-mode) for users/computers?
Who can generate resultant set of policy (planning-mode) for users/computers?
Who can change the description of organizational units?
Who can change the security permissions protecting organizational units?
Who can change the owner of organizational units?
Who can create containers?
Who can delete containers?
Who can change the description of containers?
Who can change the security permissions protecting containers?
Who can change the owner of containers?
Who can create service connection points?
Who can delete service connection points?
Who can change the keywords of service connection points?
Who can change the description of service connection points?
Who can change the binding information of service connection points?
Who can change the service DNS name of service connection points?
Who can change the service DNS type of service connection points?
Who can change the vendor of service connection points?
Who can change the version number of service connection points?
Who can change the class name of service connection points?
Who can change the security permissions protecting service connection points?
Who can change the owner of service connection points?
Who can create group policy containers?
Who can delete group policy containers?
Who can change the security permissions protecting group policy containers?
Who can change the owner of group policy containers?
Who can create contacts?
Who can delete contacts?
Who can change the security permissions protecting contacts?
Who can change the owner of contacts?
Who can create (publish) printers?
Who can delete published printers?
Who can change the description of published printers?
Who can change the share name of published printers?
Who can change the security permissions protecting published printers?
Who can change the owner of published printers?
Who can change the security permissions protecting the domain root?
Who can change the owner of the domain root?
Who can replicate secrets (i.e. password hashes) from the domain?
Domain User Account Management Reports -
Domain Computer Account Management Reports -
Domain Security Group Management Reports -
Active Directory Domain Password Policy and Account Lockout Policy Management Reports -
Organizational Unit Management Reports -
Container Management Reports -
Service Connection Point Management Reports -
Group Policy Management Reports -
Contact Management Reports -
Published Printer Management Reports -
Domain Root and Domain Security Management Reports -
––––––––––
5. Reports available in Active Directory Permissions Analyzer
Who has what permissions on an Active Directory object?
Who has what permissions in an Active Directory tree?
6. Reports available in Active Directory ACL Analyzer and Exporter
View the ACL of an Active Directory object
View the SACL (System ACL) of an Active Directory object
Export ACLs of all objects in an Active Directory tree
Export SACLs (System ACLs) of all objects in an Active Directory tree
7. Reports available in Active Directory Membership Auditor
View the direct membership of an Active Directory security group
View the complete nested membership of an Active Directory security group
View the complete list of all Active Directory security groups to which a user belongs
8. Reports available in Active Directory Security Auditor
List of all domain user accounts
List of all enabled domain user accounts
List of all disabled domain user accounts
List of all locked domain user accounts
List of all unlocked domain user accounts
List of all administrative domain user accounts
List of all domain user accounts that have logged on in the last [ X ] days
List of all domain user accounts that have not logged on in the last [ X ] days
List of all domain user accounts that have never logged on
List of all domain user accounts that have logged on at least once
List of all domain user accounts that have failed a logon attempt in the last [ X ] days
List of all domain user accounts created in the last [ X ] days
List of all domain user accounts changed in the last [ X ] days
List of all domain user accounts deleted in the last [ X ] days
List of all domain user accounts that have an expiration date
List of all domain user accounts that do not have an expiration date
List of all domain user accounts that expired in the last [ X ] days
List of all domain user accounts that will expire in the next [ X ] days
List of all domain user accounts that require passwords to logon
List of all domain user accounts that do not require passwords to logon
List of all domain user accounts whose passwords never expire
List of all domain user accounts whose passwords must be changed at next logon
List of all domain user accounts whose passwords have changed in the last [ X ] days
List of all domain user accounts whose passwords have not changed in the last [ X ] days
List of all domain user accounts whose passwords are stored using reversible encryption
List of all domain user accounts that require Smart cards for login
List of all domain user accounts that are marked 'sensitive and cannot be delegated'
List of all domain user accounts that are not marked 'sensitive and cannot be delegated'
List of all domain user accounts that can logon to any workstation
List of all domain user accounts that can only logon to specific workstations
List of all domain user accounts for which specific logon hours have not been specified
List of all domain user accounts for which specific logon hours have been specified
List of all domain user accounts that can logon anytime
List of all domain user accounts for which a logon script is specified
List of all domain user accounts for which no logon script is specified
List of all domain user accounts for which no description is specified
List of all security groups
List of all builtin security groups
List of all domain local security groups
List of all global security groups
List of all universal security groups
List of all administrative security groups
List of all security groups created in the last [ X ] days
List of all security groups changed in the last [ X ] days
List of all security groups deleted in the last [ X ] days
List of all security groups that cannot be deleted
List of all security groups that have members
List of all security groups for which no manager is designated
List of all security groups for which no description is specified
List of all domain computer accounts
List of all enabled domain computer accounts
List of all disabled domain computer accounts
List of all domain computer accounts that have authenticated on in the last [ X ] days
List of all domain computer accounts that have not authenticated on in the last [ X ] days
List of all domain computer accounts that have never authenticated
List of all domain computer accounts that have authenticated at least once
List of all domain computer accounts created in the last [ X ] days
List of all domain computer accounts changed in the last [ X ] days
List of all domain computer accounts deleted in the last [ X ] days
List of all domain controllers
List of all domain computer accounts that are trusted for delegation
List of all domain computer accounts that are trusted for unconstrained delegation
List of all domain computer accounts for which no description is specified
List of all domain computer accounts for which no manager is designated
List of all organizational units
List of all organizational units created in the last [ X ] days
List of all organizational units changed in the last [ X ] days
List of all organizational units deleted in the last [ X ] days
List of all organizational units for which no manager is designated
List of all organizational units for which no description is specified
List of all containers
List of all containers created in the last [ X ] days
List of all containers changed in the last [ X ] days
List of all containers deleted in the last [ X ] days
List of all containers for which no description is specified
List of all group policy objects
List of all enabled group policy objects
List of all disabled group policy objects
List of all group policy objects whose user settings are disabled
List of all group policy objects whose computer settings are disabled
List of all group policy objects whose user and computer settings are disabled
List of all group policy objects created in the last [ X ] days
List of all group policy objects changed in the last [ X ] days
List of all group policy objects deleted in the last [ X ] days
List of all printers published in Active Directory
List of all printers published in Active Directory in the last [ X ] days
List of all printers published in Active Directory which changed in the last [ X ] days
List of all printers published in Active Directory that were deleted in the last [ X ] days
List of all contacts
List of all contacts created in the last [ X ] days
List of all contacts changed in the last [ X ] days
List of all contacts deleted in the last [ X ] days
List of all service connection points
List of all service connection points created in the last [ X ] days
List of all service connection points changed in the last [ X ] days
List of all service connection points deleted in the last [ X ] days
List of all service connection points for which no keywords are specified
List of all service connection points for which no DNS service name is specified
List of all service connection points for which no service bindings are specified
List of all objects
Domain User Account Management Reports -
Domain Security Group Management Reports -
Domain Computer Account Management Reports -
Organizational Unit Management Reports -
Container Management Reports -
Group Policy Management Reports -
Published Printer Management Reports -
Contact Management Reports -
Service Connection Point Management Reports -
Domain Management Reports -
-- End of Reports --
Our Global Customers
Corporate Headquarters
620 Newport Center Drive, Suite 1100
Newport Beach, CA. 92660. USA.
Telephone: 001-949-468-5770















