How to Use File System (NTFS) Reports

File System (NTFS) is a top-level page in AD Reports for auditing folder and file permissions on local drives and UNC paths. Unlike every other report category, it runs without selecting a domain — so it works on standalone servers, on machines that aren't domain-joined, and when no domain controller is reachable.

Moved in 7.5.3.0. NTFS reports used to live inside AD Reports. They now have their own File System (NTFS) section in the left navigation, and your custom NTFS reports moved with them. If you had custom NTFS reports listed under Custom User Reports, that's where they are now — nothing was lost.
1

Choose a Folder or Path

Open File System (NTFS) from the left navigation. Enter or browse to the path you want to audit — a local folder (D:\Shares\Finance), a whole drive (C:), or a UNC path (\\fileserver\Finance).

Set how deep to scan with the Sub-folders setting, and use Max rows (next to the folder path) to cap very large scans. When the limit is reached the scan stops with a clear message rather than running indefinitely.

AD Reports File System NTFS page with folder path and settings

No domain required. The File System page never contacts a domain controller — including for scheduled runs. Report settings also save and load without a domain selected, and folders you saved in earlier versions migrate automatically the first time you start 7.5.3.0.
2

Run a Report

Pick a report from the tree and click Run on the ribbon. Use Cancel to stop a scan that is taking longer than expected — it stops cleanly mid-scan and keeps whatever it has already found.

Reports fall into two groups:

  • Folder permission reports — access control on directories, inheritance, ownership and auditing.
  • File permission reports — the same detail at file level.

Browse the full list in the Folder Permissions and File Permissions report library pages.

3

Four Security Reports Worth Running First

These answer the questions that come up in almost every file-server audit:

  • Orphaned SID Permissions — deleted accounts still sitting on the ACL as raw SIDs. Ghost permissions that accumulate silently over years.
  • Open Access — grants to Everyone, Authenticated Users or Domain Users. The fastest way to find shares that are effectively open to the whole company.
  • Broken Inheritance — folders where inheritance is disabled, listed with the permissions actually in force there, so you can see what the exception really grants.
  • Folder Owners — one row per folder with its owner, for establishing data ownership across a share.

AD Reports NTFS security reports results

4

Customize and Save Your Own Reports

Click Customize Report on the ribbon to open the wizard and choose which columns to include and in what order. From there you can:

  • Save as New Custom Report — your report joins the tree under File System (NTFS)
  • Save and load settings files to reuse a configuration elsewhere
  • Rename or delete your custom NTFS reports
Customization returned in 7.5.3.0 — NTFS reports had temporarily lost the wizard when the category was reorganized.
5

Export and Schedule

The Export button on the ribbon offers the same formats as every other page — Excel, Clean Excel, CSV, PDF, HTML, MHT, RTF, Text and Print Preview.

NTFS reports can also be scheduled like any other report. Because they never contact a domain controller, a scheduled NTFS report runs successfully even when no domain is reachable — useful on isolated file servers. See How to Schedule Reports.

Audit (SACL) reports need Administrator rights. If you run one without them, AD Reports now tells you plainly that elevation is required instead of failing with an error.
Questions about File System (NTFS) reports? Please feel free to contact us.
Ready to Try AD Reports?

Download the free 14-day trial and audit your file server permissions today.

Download Free Trial Browse Report Library