Paramount Defenses Header: Active Directory Reporting Tools
Paramount Defenses Inc. Logo
Company | Vision | Leadership | Products | Services | Support | News | Careers | Contact
Paramount Defenses Inc. - Most Innovative New Company Award by RSA Conference 2007

2007
Paramount Defenses - World’s Most Innovative Companies, Fast 50 Readers Favorites of 2008
2008
Microsoft Corporation Valued Partner - Paramount Defenses Inc. Valued Partner in the Identity and Access Management

2009
Learn more about this Serious Active Directory Security Risk
Start Here
Overview
Uniqueness
Vital Need
Audience
Features
Benefits
Solutions
Reports
Editions
Resources
Demo
Trial
Sales


Only Gold Finger can generate accurate Active Directory resultant-access reports, and basic security reports.

Mission-Critical
Access Reports
Top 100
Reports
Simple Basic
Security Reports


Active Directory ACL Management Security Permissions Reports

Gold Finger offers the following Active Directory based access control list (ACL) / security permissions management reports –

Active Directory Access Control List (ACL) Management Reports

NOTE If you have yet to generate access reports in your Active Directory environment, in all likelihood, there are far great risks that your Active Directory is exposed to today, than the simplistic risks you may be looking to identify and mitigate via these basic security reports.

In fact, your Active Directory may be substantially exposed to the risk of swift and complete compromise.



    Gold Finger automatically displays the Object-Type of and the total ACE count for the security principal on each object.



  1. All Active Directory objects on which a security principal has any permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has any permissions specified.

  2. All Active Directory objects on which a security principal has Allow permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has any type of Allow permissions.

  3. All Active Directory objects on which a security principal has Deny permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has any type of Deny permissions.

  4. All Active Directory objects on which a security principal has Explicit permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has any type of Explicit permissions.

  5. All Active Directory objects on which a security principal has Inherited permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has any type of Inherited permissions.

  6. All Active Directory objects on which a security principal has List Child permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has List Child permissions for a specific object class or any class of child objects.

  7. All Active Directory objects on which a security principal has List Object permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has List Object permissions for a specific object class or any class of child objects.

  8. All Active Directory objects on which a security principal has Read Property permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Read Property permissions for a specific property, for any property or for all properties.

  9. All Active Directory objects on which a security principal has Write Property permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Write Property permissions for a specific property, for any property or for all properties.

  10. All Active Directory objects on which a security principal has Create Child permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Create Child permissions for a specific object class, for any object class or for all object classes.

  11. All Active Directory objects on which a security principal has Standard Delete permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Standard Delete permissions.

  12. All Active Directory objects on which a security principal has Delete Child permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Delete Child permissions for a specific object class, for any object class or for all object classes.

  13. All Active Directory objects on which a security principal has Delete Tree permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Delete Tree permissions.

  14. All Active Directory objects on which a security principal has Read Permissions permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Read Permissions permissions, which would let the security principal read the object's access control list.

  15. All Active Directory objects on which a security principal has Modify Permissions permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Modify Permissions permissions, which would let the security principal changed the object's access control list.

  16. All Active Directory objects on which a security principal has Modify Owner permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Modify Owner permissions, which would let the security principal modify the object's ownership.

  17. All Active Directory objects on which a security principal has Extended Right permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Extended Rights permissions (such as Reset-Password) for a specific extended right, for any extended right or for all extended rights.

  18. All Active Directory objects on which a security principal has Validated Write permissions

    This report lets you identify all objects in an Active Directory domain, container or organizational unit on which a security principal (i.e. any domain user/computer account, security group, or well-known SID) has Validated Write permissions (such as Validated-DNS-Host-Name) for a specific validated write, for any validated write or for all validated writes.

Account Management
Computer Management
Group Management
OU Management
Container Management
SCP Management
GPO Management
Exchange Management
Contact Management
Printer Management
Schema Management
Trust Management
AD ACL Management
Top-100 Reports

Top-100 Active Directory Reports



(Downloadable pdf)
Contact Us
Who We Are What We Do How We Protect You
Home

Copyright Paramount Defenses Inc. 2006 – 2011. All Rights Reserved.