TopNet247Independent notes for Windows admins

Review · Active Directory Management & Auditing

Netwrix Auditor review — change auditing for AD, Group Policy and file servers

A commercial auditing platform that collects and normalises changes and access events from Active Directory, Group Policy, file servers, Windows Server and more into searchable who-what-when-where reports.

TopNet247 desk review, written independently: this is not the official Netwrix website, and Netwrix Auditor is neither hosted nor distributed here.

Visit the Netwrix product page netwrix.com

Netwrix Auditor interactive search with Who, Action, What, When and Where filters over file-server changes
Netwrix Auditor by NetwrixSource: Official site — netwrix.com
Desk card · AD
Developer
Netwrix
Licence
Platforms
On-premises; installs on Windows Server 2012 R2–2025 or Windows 10/11 (not on a DC)
Stand-out feature
Who-changed-what-when reports and alerts for AD, Group Policy, logons and file servers
Best for
Organisations that must answer auditors and need change history kept beyond event-log retention
Chore
Answering “who changed this group / GPO / file permission, and when” without trawling DC logs
Rights
A data-collection account with read access to logs and configuration; audit policy set on DCs
Trail
It is the trail: collects and archives change and logon records for reports and alerts

Tuesday morning, a department can’t reach its share. Someone removed the Finance group from the folder’s ACL, and someone else — or the same person — edited a GPO that drives drive mappings. Event Viewer has the raw material: 4670 for permission changes if you had object access auditing on, 5136 for the GPO’s AD object, 4662 for the directory access. What it doesn’t have is a sentence that says “CORP\adm-tlee changed the NTFS permissions on D:\Shares\Finance at 17:42 yesterday, old value / new value”. Netwrix Auditor produces that sentence, for AD, Group Policy, file servers and a long list of other systems.

What it does

Netwrix Auditor collects audit data from supported systems, normalises it into a common “who, what, when, where, old value, new value” format and stores it for search, alerting and reports. The vendor lists sources including Active Directory, Group Policy, Exchange, Microsoft 365 and Entra ID, SharePoint, Windows file servers and several NAS platforms, Windows Server itself, SQL Server, Oracle, VMware and network devices.

For a Windows domain admin, the core uses are:

  • AD and Group Policy change reports with before/after values — including which GPO setting changed, not only that the GPO object was modified.
  • File server activity — reads, changes, deletes and permission changes, which is what you need after an accidental mass delete or a ransomware scare.
  • Logon activity — successful and failed logons across the domain, including RDP.
  • State-in-time reports — what group memberships or permissions looked like on a given date, useful for access reviews.
  • Alerts — for example, an email when someone is added to Domain Admins.
  • Interactive search — a Google-style query over all collected events.

At the time of writing the current release is version 10.9 (June 30, 2026), which added state-in-time reporting and risk assessment for Azure Files; 10.8 shipped in July 2025.

Rights, prerequisites and the audit trail

This is an auditing product, so its requirements are mostly about making Windows record enough. Plan for:

  1. A dedicated Windows Server for the Auditor server, plus Microsoft SQL Server for the audit database and SQL Server Reporting Services for reports. SQL Express works for small estates but its database size limit fills quickly.
  2. Audit policy. Netwrix can configure it automatically or you set it via GPO: Advanced Audit Policy for account management, directory service changes and logon events, and object access auditing plus SACLs on the folders you monitor. Increase Security log sizes on DCs so events survive until collection.
  3. A data collection account with the rights each source needs. For AD, that means reading the Security log and the directory, which is less than Domain Admin, and the vendor documents the minimal set. Use a group-managed service account where the documentation allows.
  4. Network access from the Auditor server to DCs and file servers over RPC and SMB, plus SQL traffic to the database.

Collection is largely agentless and based on native logs, though some sources support optional agents or compression services to cut network traffic on busy servers. The long-term archive and SQL database become sensitive records themselves — protect them like backups, restrict report access, and define retention to match policy.

Use with your organisation’s authorization and a documented purpose. File and logon activity data describes what individuals did; handle it under your privacy and HR policies, not as ad-hoc browsing.

Where it’s strong

  • Clear before/after reporting for AD and Group Policy, which native logs make painful.
  • Many sources in one search, so a single question can span AD, a file server and Microsoft 365.
  • Compliance report packs that map to common frameworks and satisfy auditors quickly.
  • Alerts on high-risk changes such as privileged group membership.

Where it falls short and who should skip it

It records; it doesn’t manage or roll back most changes, so you still need AD tooling to fix what it reveals. The footprint is real: a server, SQL Server and SSRS, audit policy tuning, SACL design and ongoing capacity planning for busy file servers. Pricing is quote-based except for small-business self-service, so budgeting takes a sales conversation. If you already run a SIEM with Windows Event Forwarding and good parsing, much of the value overlaps. And a 20-user office with a single DC is likely better served by native audit policy plus a few saved Get-WinEvent queries.

Who it suits

Mid-size organisations with regulatory or insurance-driven audit requirements, several admins with elevated rights, and file servers holding sensitive data. It is also a strong fit for teams recovering from an incident who realise they couldn’t say who did what.

Licensing and cost

Netwrix offers subscription and perpetual licences with quote-based pricing that depends on product and deployment model. At the time of writing, a self-service checkout for an Essentials Edition is available to organisations with up to 150 employees, and a 14-day free trial “with full access” is offered. No per-unit list prices are published. Check the vendor’s current pricing page for details.

How it compares

ManageEngine ADManager Plus manages AD with delegated workflows; Netwrix Auditor watches everything that changes, including changes made outside any tool. The trade-offs are in ADManager Plus vs Netwrix Auditor. For RDP-only logon history at a lower price, Remote Desktop Audit covers a narrow slice. Native options start with RSAT and event logs; see pull RDP logon history from event logs. More in Active Directory Management & Auditing.

Getting it safely

Get Netwrix Auditor or a trial through Netwrix’s own website. Verify the package’s digital signature before running, and deploy on a hardened server with restricted access. See where to get it for our general checklist.

FAQ

Does Netwrix Auditor need agents on domain controllers?

Collection is primarily agentless using native logs. Some sources offer optional agents or compression services to reduce traffic; check the documentation for your version and source.

Which database does it use?

Microsoft SQL Server for the audit database, with Reporting Services for reports, plus a file-based long-term archive.

Can it show what a Group Policy setting was before a change?

Yes, before/after values for GPO settings are one of its core AD features.

Is there a free edition?

At the time of writing the vendor offers a 14-day full trial and separate free utilities, but no free edition of Auditor itself.

Same drawer

Tools to weigh against Netwrix Auditor