How To Save Report Snapshots and Compare Changes Over Time
Save any AD or Azure report as a baseline and compare it later to see exactly what changed
in your directory. Comparison opens a dedicated Diff tab showing
Added, Removed, and Changed sub-tabs with side-by-side
(was) and (now) columns. Snapshots persist across app restarts so you can
compare today's results against last week, last month, or your last security audit.
Save the Active Report as a Baseline
Run any AD or Azure report. When the results are loaded in the Results tab, click the new History button on the Results toolbar and choose Save Active Report to History.
AD Reports stores the snapshot with a timestamp and report name so you can identify it later. The snapshot includes only the columns you ran — if you change column selection later, the original snapshot is unchanged.
Compare the Active Report with a Saved Baseline
Run the same report again (or open an existing Results tab) and click History → Compare Active Report with Saved…. AD Reports lists all snapshots that match the current report — pick a baseline by timestamp and click Compare.
A new Diff tab opens with three sub-tabs and a header summary showing the totals and the timestamps of both runs.
Read the Diff Tab
The Diff tab has three sub-tabs:
- Added — accounts or objects that appeared since the baseline (new users, new group members, new computers, etc.).
- Removed — accounts or objects that disappeared since the baseline (deleted, moved out of scope, or filtered out).
- Changed — same accounts but with field changes, shown side-by-side as
(was)and(now)columns. The columns that actually changed are highlighted so you can spot the diff at a glance.
The header at the top of the Diff tab shows the totals: Added: N · Removed: N · Changed: N · Unchanged: N, plus the timestamps of the baseline and the current run.
Each sub-tab is a normal grid — you can sort, filter with the Find Panel, copy to clipboard, and export to Excel or CSV. Filenames include both timestamps so you can tell which baseline was used.
Manage Saved Snapshots
Click History → Manage Saved Snapshots… to open the management dialog. You can:
- Review every saved snapshot grouped by report name with timestamps and row counts
- Delete an individual snapshot you no longer need
- Bulk-delete anything older than 30 days with one click
Common Use Cases
- What changed since our last security audit? Save a baseline of Members of Domain Admins, Shadow Admins, and Service Accounts with SPNs right after each audit. The next quarter, run the same reports and compare — you'll see every privilege change in seconds.
- Did the cleanup remove what we expected? Snapshot Disabled Users or Inactive Computers before the cleanup run. Compare immediately after — the Removed sub-tab is your verified deletion list.
- Who got added to Domain Admins this month? Schedule a monthly snapshot of the relevant report (or save manually before each change-control meeting). Compare to the previous baseline — the Added sub-tab is your monthly privilege-creep report.
- Hybrid Identity drift over time. Snapshot the Cloud-Only Privileged Admins and UPN Suffix Mismatches Hybrid Identity views. Each compare shows what shifted between on-prem and Entra without manual diffing.