For the best web experience, please use IE11+, Chrome, Firefox, or Safari

Change Auditor for Active Directory

Monitor and secure AD with Active Directory auditing tools. Ensure the security, compliance and control of your hybrid AD environment with Change Auditor for Active Directory. Track, audit, report and alert on all key configuration changes and consolidate them in a single console — without the overhead of turning on Microsoft-provided auditing. Proactively protect objects and track all changes in real time with security threat monitoring.
Active directory auditing tools: Change Auditor for Active Directory
Change Auditor for Active Directory
Without effective Active Directory (AD) auditing tools, you will face AD issues that can result in unplanned and costly service disruptions and business-impairing network downtime. Harmful data breaches and non-compliance with GDPR, PCI, HIPAA, SOX and more can cause you to incur hefty costs as well. You need Active Directory security auditing that ensures you’re notified in real time of critical changes to AD, Azure AD and ADFS configuration. Change Auditor for Active Directory makes that all possible.

Hybrid AD auditing

Get a single, correlated view of all AD and Azure AD activity, with visibility of all changes whether on-prem or in the cloud.

Security threat monitoring

Audit and block exploits such as AD database copies via NinjaCopy and credential theft via unauthorized domain replication.

Object protection

Protect against changes to critical Active Directory objects, such as accidentally deleted OUs and modified GPO settings.

Normalized 5W audit details

Translate cryptic native logs into a simple, normalized format highlighting the who, what, when, where and workstation details and before and after values.

Account lockout

Capture the originating IP address/workstation name for account lockout events to simplify troubleshooting.

Real-time alerts on the move

Send critical change and pattern alerts to email and mobile devices to prompt immediate action, even while you're not on site.

SIEM integration

Integrate with SIEM solutions to forward Change Auditor events to Splunk, ArcSight, QRadar or any platform supporting Syslog.

Auditor-ready reporting

Generate comprehensive reports to support regulatory compliance mandates for GDPR, PCI DSS, HIPAA, FISMA / NIST, SOX, GLBA and more.

On Demand Audit Hybrid Suite for Office 365

With just a few clicks, you can pair Change Auditor for Active Directory and Change Auditor for Logon Activity with On Demand Audit to get a single, hosted view of all changes made across AD, Azure AD, Exchange Online, SharePoint Online, OneDrive for Business and Teams. Simplify investigations with responsive search and interactive data visualization, and retain audit history for up to 10 years.


Superior auditing engine

Remove auditing limitations and captures change information without the need for native audit logs, resulting in faster results and significant savings of storage resources.

Security threat timelines

View, highlight and filter change events and discover their relation to other threat events in chronological order across your AD and Azure AD environment for better forensic analysis and security incident response.

Related searches

This active directory auditing tool provide instant, one-click access to all information on the change you're viewing and all related events, such as what other changes came from specific users and workstations, eliminating additional guesswork and unknown security concerns.

AD-change rollback

Restore previous values on unauthorized, mistaken or improper changes with the click of a button, directly in the Change Auditor console, honoring the rights and privileges of the user requesting the rollback.

Quest InTrust integration

Integrate active directory auditing tools with Quest InTrust for 20:1 compressed event storage and centralized native or third-party log collection, parsing and analysis with alerting and automated response actions to suspicious events such as known ransomware attacks or fishy PowerShell commands.

Improved security insights

Correlate disparate IT data from numerous systems and devices into IT Security Search, an interactive search engine for fast security incident response and forensic analysis. Include user entitlements and activity, event trends, suspicious patterns and more with rich visualizations and event timelines.

Large Retail Chain

Change Auditor object protection is a lifesaver. I have it set up to prevent changes to the ACLs on certain directories on our file servers, as well as to protect all administrative accounts. We’ve had pen testers come in and be very surprised that they could not get past the Change Auditor object protection

Enterprise Administrator, Large Retail Chain Read Case Study

AFV Beltrame Group

With Change Auditor, we achieved our goal of gaining complete and centralized visibility of security audit operations across the entire Group — including not just our on-premises Windows file servers and domain controllers but also our Office 365 services, such as mail, SharePoint Online and OneDrive for Business

Mirco Destro CIO and IT Manager, AFV Beltrame Group Read Case Study

Region Halland

Previously, investigating an issue could easily take an hour. Change Auditor cuts that time to just 5–10 minutes.

Dennis Persson IT Systems Technician, Region Halland Read Case Study


Group Policy
Account lockout
Object protection
Role-based access
Hosted dashboard with On Demand Audit


Alert on and monitor critical changes made to Active Directory.

Stevie Awards 2018 People’s Choice winner

In the 2018 Stevie Award’s People Choice awards, Change Auditor was voted best software and also won a Silver Stevie for best new product of 2018


There are specific system requirements for the Change Auditor coordinator (server-side), Change Auditor client (client-side), Change Auditor agent (server-side), and the Change Auditor workstation and web client (optional components). For a full list of system requirements and required permissions for all components and target systems that can be audited by Change Auditor please refer to the Change Auditor Installation Guide.

The Change Auditor coordinator is responsible for fulfilling client and agent requests and for generating alerts.


Quad core Intel® Core™ i7 equivalent or better


Minimum: 8 GB RAM or better

Recommended: 32 GB RAM or better

SQL Server

SQL databases supported up to the following versions:

  • Microsoft SQL Server 2012 SP4
  • Microsoft SQL Server 2014 SP3
  • Microsoft SQL Server 2016 SP2
  • Microsoft SQL Server 2017
  • Microsoft SQL Server 2019
  • Azure SQL Managed Instance (PaaS) with SQL authentication or Azure Active Directory authentication

NOTE: Performance may vary depending on network configuration, topology, and Azure SQL Managed Instance configuration.

NOTE: Change Auditor supports SQL AlwaysOn Availability Groups, SQL Clusters, and databases that have row and page compression applied.

Operating system

Installation platforms (x64) supported up to the following versions:

  • Windows Server 2012
  • Windows Server 2012 R2
  • Windows Server 2016
  • Windows Server 2019

NOTE: Microsoft Windows Data Access Components (MDAC) must be enabled. (MDAC is part of the operating system and enabled by default.)

Coordinator software and configuration

For the best performance, Quest strongly recommends:

  • Install the Change Auditor coordinator on a dedicated member server.
  • The Change Auditor database should be configured on a separate, dedicated SQL server instance.

NOTE: Microsoft ODBC Driver 17 for SQL Server is required when the Change Auditor database resides on Azure SQL Managed Instance and Azure Active Directory authentication is selected.

NOTE: Do NOT pre-allocate a fixed size for the Change Auditor database.

In addition, the following software/configuration is required:

  • The coordinator must have LDAP and GC connectivity to all domain controllers in the local domain and the forest root domain.
  • x64 version of Microsoft’s .NET 4.7.1
  • x64 version of Microsoft XML Parser (MSXML) 6.0
  • x64 version of Microsoft SQLXML 4.0
Coordinator footprint
  • Estimated hard disk space used: 1 GB.
  • Coordinator RAM usage is highly dependent on the environment, number of agent connections, and event volume.
  • Estimated database size will vary depending on the number of agents deployed and audited events captured.

Additional Account Coordinator minimum permissions required, please see Change Auditor Installation Guide .


Get started now

Improve AD security and compliance auditing.

Support and services

Product Support

Self-service tools will help you to install, configure and troubleshoot your product.

Support Offerings

Find the right level of support to accommodate the unique needs of your organization.

Professional Services

Search from a wide range of available service offerings delivered onsite or remote to best suit your needs.

Education Services

Training courses delivered through online web-based, on-site or virtual instructor-led.