Skip to main content
TrustRadius
ManageEngine ADAudit Plus

ManageEngine ADAudit Plus

Overview

What is ManageEngine ADAudit Plus?

ADAudit Plus offers real-time monitoring, user and entity behaviour analytics, and change audit reports that helps users keep AD and IT infrastructure secure and compliant.Track all changes to Windows AD objects including users, groups, computers, GPOs, and OUs.Achieve hybrid AD monitoring with…

Read more
Recent Reviews

Good tool

8 out of 10
February 29, 2024
Incentivized
Auditing Admin Activities, Ransomware Protection, Auditing malicious user activities, and changes on systems. The audit tracking from …
Continue reading

ADAudit Plus Review

9 out of 10
February 24, 2024
Incentivized
We have two products. One for the Domain controllers and the second for the file servers. ADAudit Plus collects all of our data, logs, …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 15 features
  • Data visualization (42)
    9.0
    90%
  • Administrator access control (45)
    8.8
    88%
  • Customizable reporting (47)
    7.8
    78%
  • Automated alerts and notifications (45)
    7.1
    71%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

Standard

$595

On Premise
per year

Professional

$945

On Premise
per year

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.manageengine.com/products/a…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Starting price (does not include set up fee)

  • $595 per year
Return to navigation

Features

Monitoring Tasks

Various types of monitoring

7.8
Avg 8.4

Management Tasks

Various tasks required to keep systems running smoothly

8.9
Avg 8.4

Reporting

Report generation to help with system monitoring tasks

8.5
Avg 8.3

Security

Management of security aspects of system monitoring

6.6
Avg 7.6
Return to navigation

Product Details

What is ManageEngine ADAudit Plus?

ADAudit Plus offers real-time monitoring, user and entity behaviour analytics, and change audit reports that helps users keep AD and IT infrastructure secure and compliant.

  • Track all changes to Windows AD objects including users, groups, computers, GPOs, and OUs.
  • Achieve hybrid AD monitoring with a single, correlated view of all the activities happening across both on-premises AD and Azure AD.
  • Monitor every user's logon and logoff activity, including every successful and failed login attempt across network workstations.
  • Audit Windows file servers, failover clusters, NetApp, and EMC storage to document changes to files and folders.
  • Monitor system configurations, program files, and folder changes to ensure file integrity.
  • Track changes across Windows servers, printers, and USB devices with a summary of events.
  • Leverage advanced statistical analysis and machine learning techniques to detect anomalous behaviour and defend against cyber attacks.

ManageEngine ADAudit Plus Features

Monitoring Tasks Features

  • Supported: Remote monitoring
  • Supported: Network device monitoring
  • Supported: Multiple Server Monitoring
  • Supported: Multi-device monitoring
  • Supported: Automated alerts and notifications

Management Tasks Features

  • Supported: Service configuration management
  • Supported: Policy-based automation

Reporting Features

  • Supported: Performance data reports
  • Supported: Customizable reporting
  • Supported: Data visualization
  • Supported: Risk analysis

Security Features

  • Supported: Administrator access control

ManageEngine ADAudit Plus Screenshots

Screenshot of Active Directory AuditingScreenshot of Track Account LockoutsScreenshot of Logon MonitoringScreenshot of Audit User PrivilegesScreenshot of PCI - DSS Compliance

ManageEngine ADAudit Plus Video

Redinet's testimonial about ManageEngine ADAudit Plus

ManageEngine ADAudit Plus Technical Details

Deployment TypesOn-premise
Operating SystemsWindows
Mobile ApplicationApple iOS, Android, Windows Phone
Supported CountriesGlobal
Supported LanguagesEnglish

Frequently Asked Questions

ManageEngine ADAudit Plus starts at $595.

Netwrix Auditor, SolarWinds Access Rights Manager (ARM), and Splunk User Behavior Analytics (UBA) are common alternatives for ManageEngine ADAudit Plus.

Reviewers rate Multiple Server Monitoring highest, with a score of 9.2.

The most common users of ManageEngine ADAudit Plus are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(114)

Attribute Ratings

Reviews

(1-25 of 35)
Companies can't remove reviews or game the system. Here's why
February 27, 2024

ManageEngine ADAudit Plus

Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use this to track and managed failed/unusual sign ins and unusual activity within our estate
  • User Audit tracking - logon/log off events
  • unusual azure logon activity
  • unusual file activity
  • AD changes
  • Easier understanding of report creation
  • more modern interface
ManageEngine ADAudit Plus is useful in identifying who changed what and when within AD and Azure AD. It is helpful in identifying why logins fail and allow easier resolution. Tracking of anomalous behaviour.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We Use ADAudit Plus to audit our AD on-prem and see who did what on accounts. This also allows us to track login attempts from an external source. We also use this platform to help manage stale accounts and accounts with too much privilege. We are also able to see what server users and admins are logging in.
  • User id tracking and modification.
  • Who logged in to what.
  • How many failed attempts per user.
  • Reporting from longer term faster.
  • GUI could be improved.
  • More customizable dashboard.
We detected that a person was logged into a server with his regular credentials when he should not have been able to since only admin accounts are allowed to do so. We saw a user getting locked accounts all the time, logging into a server, and then logging out. After he changed his password twice, the account locked out due to the login.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use ManageEngine ADAudit Plus as a security layer for AD activity audits, automatic detection of anomalous behavior, and also as a research tool to find users vs. computers.
  • Identify unusual logins to AD, such as after hours, for example.
  • Detailed audit of user changes in AD, like account change auditing, group policy changes auditing
  • Custom Reports and Alerts
  • No changes required.
  • No changes required.
  • No changes required.
ADAudit Plus is suitable for any size of company, due to its licensing format, but I believe that in more complex scenarios, for companies that take information security seriously, it is indispensable.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
i use ManageEngine ADAudit Plus to my Siem integration. also, i use it when i asked for to see who deleted file and folder and when. it even used me once to troubleshot deleted files by service account.
  • audit ad changes
  • audit deleted files
  • map service users
  • 1 click setting
  • if there is new dc, it should be added automatically
security scenarios. more than once, i used it to see changes in gpo, enabled account , etc...
Score 9 out of 10
Vetted Review
Verified User
Incentivized
This product is used to monitor anything to do with AD
We rely on the alerts of new and disabled users as verification of our automation system.
We use the feature of Auditing selected key servers to find out when permissions change and by who.
  • Email alerts
  • Reviewing folder change permissions
  • AD permissions change reports
  • Auto update of the product
Track changes on our files servers
Track logons on servrs
Track administrator changes
Track admin AD changes
February 26, 2024

Great bang for the buck.

Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use it mostly for an information trail. It helps us troubleshoot, accidental deletions on our file server and changes to our Active Directory environment. Recently have been setting up more alerting around permission changes on objects and User creation activities.
  • Logging
  • Reporting
  • Alerting
  • Steep learning curve
  • alerting customization
It is very cost effective solution, it covers most of our needs compared to competitors at a fraction of the price. It requires a bit of work to get to a great place as far as relevant information
February 26, 2024

AD Auditing Easily

Neil Shepherd | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use ManageEngine ADAudit Plus to keep a record of logins in our data centre. This is data that we could never keep track of manually and the product does a great job. There are also some users who may not work outside of their specific hours. This allows us to report on this effectively. A 3rd aspect is troubleshooting failed RDS logins. We can track the journey more effectively.
  • Tracking user logins
  • Tracking failed logins
  • There have been occasions where the service was not running and i would not have known without logging in
  • The upgrade process could be simpler
It is most suited to keeping an eye on any potential bad actors gaining or trying to gain access
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We have used ManageEngine ADAudit Plus in our organization for quite a few years. The product provides excellent granular visibility into all things Active Directory. We use the product on a daily basis and are very happy with what we can get out of the product.
  • Audit of AD groups and GPOs
  • Alerting for audit of administrative events
  • AD lockout tracking
  • Setting up an alert for a triggered event for an AD group for example could be easier to setup
I think ManageEngine ADAudit Plus is a great fit in most any enterprise scenario.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use ManageEngine ADAudit Plus to audit our user logins, password changes, group membership changes, and a whole ton more. We utilize ManageEngine ADAudit Plus to make sure we have a log of all our administrators changes to the any file systems and also to track any rogue or hijacked accounts in the case of a security breach.
  • Auditing
  • Keeping logs of user's changes
  • A great dashboard
We have had some administrative staff make changes that were not authorized and having ManageEngine ADAudit Plus really helped us provide the evidence that they in fact made the unauthorized change. We've also had a case where some file changes were made by service accounts and that helped us figure out which ones were doing the change.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We monitor access to domain controllers and especially sensitive files on our file server. It has helped to identify when if anyone accessed or attempted to access sensitive files. It has also helped in monitoring password and username failures. We have several daily reports we use for these.
  • bad password/username monitoring
  • file access monitoring
  • logon activity monitoring
  • a security hardening section like other ManageEngine products
  • make the user interface more similar between other ManageEngine products
  • a little more detail in reports
It's been a great tool for monitoring Active Directory logins and access to files on our servers. I receive daily reports on failed logins which helps to find users with expired passwords that could be logged in to multiple computers and causing constant failed logins. As well as bad usernames which is very helpful to identify unwanted logins on computers or attempts by certain users that should not be logging in at all. We monitor access to sensitive HR and CEO files.
Ken Lubar | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use ManageEngine as an SIEM system for reporting on AD and other events. Various of our customers require SIEM systems and ManageEngine met the needs. It's pretty lightweight. We have about 50 workstations and 2 active AD controllers. Not a lot of usage against the ManageEngine but it mostly does the job. See later in the review for the good, bad, and ugly.
  • Data capture against a wide variety of sources (logs, events, windows, Linux systems)
  • Ability to find specific events in the logs
  • Basically unlimited history
  • Useful dashboard (although not really once you dig into it)
  • It's based on Java engine that is slow -- reports are often difficult to build (we are going to upgrade the machine it's running on to see if this is the issue)
  • Keeping this software up to date is a pain; there should be a better "update" function
  • The naming and navigation are terrible -- it's never clear which feature you're looking for and where it's hidden in the menus
  • Adding machines is not as easy as it should be; occasionally there are IP conflicts that are nearly impossible to resolve
ManageEngine is mostly a "check the box" solution for SIEM systems. We needed something that satisfied our customer and was cost-effective. I would highly rate the system on "worth what paid for". Support is eager to please and prompt. My only issue is that it's mostly based outside the US with helpful, but non-native speakers so it's hard to understand them. I wish they would spring for better help "phone lines" so I'm not dealing with difficult to understand and unclear speakers.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We utilize it to address a gap in logging when it comes to tracking AD changes completed by our systems & support teams.
  • User, GPO, Computer object change auditing
  • AD activity tracking/auditing such as login failures
  • LAPS password read auditing
  • Radius logging
  • Better availability of archived logs - remounting logs can be time consuming
To provide increased logging and reporting ability in the form of a cost-effective and easy-to-deploy solution. To provide a plug-and-play solution to manage even the most decentralized AD environments.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use AdAudit to centrally repository all Active Directory user and system events. And do monthly, quarterly, and yearly reporting on user interactions, permission changes, account creations, and deletions. And for helping find where people get locked out. Great tool for AD reporting all around! You can create reports in various file formats; pdf, csv, xls, etc for the necessary consumption needs.
  • AD reporting.
  • Live user account event research and review.
  • network drive access permission changes.
  • some of the reports have bugs and have been long-standing issues not resolved for years.
  • web portal has not really changed in look & feel in years.
  • not always the easiest to customize reports.
Active Directory environments ADAudit works very well. For workgroups, it won't always work the best. Pricing is very scalable for an organization of any size and growth pattern to do reporting and AD analysis. With the new offer for cloud and on-prem installation services any company can get in on this tools' use for an attractive price.
Michael Baxley | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
AD Audit plus lets our IT staff track changes and alerts to AD activities. Security events and change management are easily tracked, recorded, and reported.
  • Detects new users, privileged users.
  • Detects failed and successful login attempts.
  • Detects new computers added to domain.
  • Detects Group Policy Changes.
  • Integration with Azure could be better documented.
  • More analytics for compliance templates.
  • More flexible custom reports.
Tech support is quick to provide assistance with custom reports or configurations.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use it for checking logins and auditing account usage. When did this user login? How many times did this user try to login today? Was this user logged in at this time? The feature used mose on this product for us is login activity tracking.
  • Auditing logins and logoffs
  • Finding account lockouts
  • More azure linked tools and reports
Its been a great tool for our IT department for several years.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use it to audit the system (changes) and the techs who are in charge of doing accounts, moving accounts, creating computers. etc.
Gives us a deeper dive into the stuff that happens in AD w/out us realizing. We utilize this tool a lot!
  • Logging
  • Features available
  • Interface and layout
  • Multiple domain access
  • Server integration
  • simplify notifications
  • some feature seem clunky
Well suited in any Active Directory environment. It helps us in a bunch of different ways but most notably the actual auditing of our environment. It hits the WHO? When? Where? for us. Who made the change, when they made the change and of course where they made the change. Being able to go back over a year is also very helpful.

If you're not in an AD environment, the software is obviously not helpful but if you are...don't miss out. Implementation is a breeze, the software works great. Support is consistent. Not the best, but definitely not the worst.
Aaron Nielson | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
We use ADAudit Plus to actively monitor our on-prem and Azure instances of Active Directory. We utilize the tool to provide alert and logging functions for multiple Active Directory user events as well as detect unexpected configuration changes to our Active Directory configuration. The tool also provides detailed account reports that can be utilized as evidence during an audit. The reports contain details such as who, what and when was changed for user, computer and groups as well as objects such as GPOs, etc. The tool also provides additional functionality such as analytic alerts and reports for anomalous user activity, file and server audits and FIM. We find this tool to be invaluable in monitoring the state of our Active Directory environment and it has helped us thwart intrusion events and malicious activity. This tool is invaluable for monitoring and auditing your Active Directory environment and it is available at a very competitive price.
  • Activity reporting
  • Alerting on anomalies and unexpected events
  • Ease of deployment and configuration
  • Excellent end user support
  • Custom alerts can be difficult to write/configure
  • Would like to see more complex alerting for common AD attacks such as Kerberosting, etc.
This audit solution is appropriate for both small and large institutions. It can provide excellent audit reports that are easily obtained and provide clear details of the who, what, when. There are other solutions that are a bit more robust when it comes to detecting and alerting on malicious activity but for the cost and customizable options, ADAudit Plus is hard to beat. I have successfully used this product to detect and thwart intrusion events. If configured correctly, it can provide robust detection and alerting capabilities.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use ADAudit plus to keep tabs on everything that is happening in AD. Predefined and custom alerts allow for very granular alerting based on the things that matter most to you. Alerts happen in real-time for admin-related and other high-profile tasks that are happening in AD. There is also historical data that can be used for trending or troubleshooting. Reports can be generated for a large number of events. We also use this for file server auditing to see what users deleted, modified, moved, etc. files or folders.
  • Alerting on relevant events.
  • Report generation for specific scenarios.
  • Logging of meaningful data.
  • Correlation/Anomalous Activity checks.
  • In earlier releases there were quite a few bugs and performance issues. These have since been resolved.
  • When integrated with the Log360 Suite, it can be confusing on whether EventLog Analyzer or ADAudit Plus are "managing"/"Ingesting" the data from a given endpoint.
If you are using an Active Directory environment, this tool will complement any existing UEBA/SIEM type tools you have in place.
May 02, 2023

AD Audit Plus

Score 10 out of 10
Vetted Review
Verified User
Incentivized
We used it to audit our Active Directory as part of our Cyber Security compliance. This solution made it easier for us to grab the reports needed on a daily basis. Also once we implemented our Azure AD this will be a great add-on for that deployment.
  • Logon Failures
  • User activity
  • User Management
  • Integration with other solution of ManageEngine without SSL
  • Better UI
  • Can we get detailed activity of users
With ADAudit it just makes it easier to manage Active Directory, the visibility of all reports you can generate in just a matter of a click...try doing that from powershell.
Zwier Dijkhuis | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We are managing a large group of users and groups in multiple domains with our dedicated IT support group that consists of 5 domain admins and 35 power users. We also have a user provisioning application in-place that controls user creation and group addition/removal.
The enduser lead can manage groups for their employees using the provisioning application, all changes are audited in this application. For all the other changes that are made outside the tool we use AD Audit logging, but that is hard to manage because securitylogs ar fastly overwritten (even with high capacity log settings) and most of the time it is hard to find the specific changes you need.
Since we use ADAuditplus all these problems are gone and besides that we saw that ADauditplus had more capabilities that helped us to prefend looking in audit logs, because we now have the ability to set alerts for specific changes that we did not want to happen. For example the "password never expires" option, we dont want that to be set for any user. In ADAuditPlus I created a rule that send me and IT management an email that shows us who and when that specific change was made. We are very happy with ADauditplus, it helps us to maintain the high level security in our environment.

  • ManageEngine ADAudit Plus changes for user and group management can be looked up in builtin reports
  • You can build your own reports based on almost every logic you can think of
  • You have the ability to create alerts based on logic and filters and sendout custom alerts to email, SMS or other means.
  • First you need to understand the basics of the software, after that the software itself is very helpfull in configuring specific items.
  • I really love the support that ManageEngine is giving the customer, for all questions I use the chat on their website. This is for me the best remote support I ever saw, and I saw a lot in my 20 years of experience in IT.
  • The archive function can use some more work. When I search for data and the data is found in the archive I can push a button to retrieve it, but there is no notification when the data is fully loaded again.
  • Searching for specific data in reports it could be helpful to have a drop list of common failures when using the advanced filter option.
  • Besides the default alerts dashboard it would be nice to create your own alerts dashboards. That way I could give other people there own alerts dashboard with the alerts that are helpfull for them only.
In my opinion this is the best software for managing and controlling changes in Active Directory. Besides that it comes default with lots of very handy built in reports and alerts. And if you need more, just create one yourself. Suitable for any size of company that leans on daily changes in Active Directory and want to maintain their security at a high level.
October 28, 2022

Good for the price

Score 9 out of 10
Vetted Review
Verified User
Incentivized
As a public company we need to be able to provide evidence of changes and ADAudit has save us many hours of searching for ways to provide this. From an operational point of view being able to search and find who, when, and what changed again saves man hours when trying to figure out instances where there is a mistake or question about why a persons access was changed.
  • Tracking changes to passwords.
  • Tracking user access changes via security groups.
  • Tracking group policy changes.
  • Event driven alerting
  • Customizable dashboard
  • Smoother upgrade process. Sometime easy, sometimes clunky
Audit trails for help desk related updates to accounts. Audit tails for SysAdmin related changes to AD architecture and policy
Score 10 out of 10
Vetted Review
Verified User
Incentivized
As a member of senior staff, it is critical to monitor changes made in our environment. These changes can be intentional and have adverse effects, so we need to know why they were done. It is easy to see how a change cause a problem or resolved an issue but the changer must be tracked and accountable for these items
  • Track changes to rights
  • track changes to policies
  • check for locked out accounts
  • report again usage
  • It would be great to feed data from ADAudit Plus to ad manager and use that for changes
  • It would be great to have an sql like language to report against the data
  • It would be great to store the data 100% in the cloud
If you need basic easy to use monitoring of your director solution on ADS or AADP then this is a great tool.

I have yet to find a solution where it is not appropriate for us. The cost is right for the output so value is big.
October 27, 2022

Quick and Easy

Scott Ashenden | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We mainly use this for compliance reporting and to provide evidence for our ISO and financial audits. There are a plethora of reports to chose many of which would take us time to write scripts to pill the data but its all there are a click of a button. We also use this to report of file storage usages and has been essential when auditing file movement, deletetion etc
  • File audits
  • Active Directory Audits
  • Reports
  • Better integration with Azure AD
  • Better Sharepoint Logging
This is a great product for auditing your Active Directory, we run monthly reports for our auditors to demonstrate that we know all users created, movements and removal.
Where multipe administraors are available in Active Directory this is useful to be able to easily display actions in Active Directory, and show any changes made to Group Policies, User Groups amonst other things.
It is not so great at intergrating in with Azure AD as it is on premise but it has improved.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use it to manage the active directories. It brings powerful tools that others don't have, and it's in an extremely intuitive interface. The reports are great, and it already has all the reporting we need without using our time creating them. It's easy to create and manage custom active directory attributes, which we use on a regular basis. We also use the user delegation tools; we have given HR access so they can also make employee changes.
  • Management Delegation.
  • Reporting
  • Intuitive interface.
  • honestly, i don't know where it could improve. it has everything we need.
If you have an active directory in your business with more than just a handful of employees, you'll want ADAudit Plus. It's great for managing AD. Suppose you are in a heavily regulated field like Financial Services or Healthcare, then you will need it. The management, plus the reporting, will help you tremendously.
Daniel Paniagua | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use Audit plus for the administration and management of our active directory. We handle all reports and incidents.
  • Reporting
  • Logs
  • Alerts
  • Assets Inventory.
For auditing domain logs, users and activities. Less appropriate costs.
Return to navigation