Find out who has access to what - and why - before a breach, an auditor, or a departed employee's stale login does.
Access Auditor analyzes and assesses file and folder permissions to identify real security risk - excessive access, broken inheritance, orphaned SIDs, inactive accounts still holding logins, and paths to privilege escalation - with least-privilege remediation guidance and ongoing governance tracking. Every scan runs entirely offline, against your own file servers and shares.
The real app. Click to zoom in, hover the markers to see what each part does.
Hover a marker for details, or click the screenshot to zoom in.
Rule-based, explainable: flags broad groups and unusually wide grants so risky access doesn't stay buried in a long permission list.
Finds folders where inheritance has been explicitly disabled - a detached permission chain that's easy to lose track of over time.
Surfaces access control entries whose identity no longer resolves to a live account - access left behind by a departed user or deleted group.
Flags accounts that still hold live access but haven't logged in for an extended period - exactly the kind of stale credential attackers look for.
Traces group nesting and inherited grants to find paths where a low-privilege account can end up with far more access than intended.
Least-privilege remediation recommendations, a risk score per finding, and a governance review workflow with full scan history and scheduled scans.
Pick the depth of audit you need, then choose once-off or monthly billing. Access Auditor licenses per machine, not by data volume.
One-time payment - yours to keep, no subscription.
For a first look at where access is too broad.
Excessive Access Detection across a full recursive scan of any local path, mapped drive, or mounted share.
For catching the structural problems too.
Everything in Standard, plus Broken Inheritance Detection and Orphaned SID Detection.
For finding the risks that don't show up in a plain ACL list.
Everything in Standard+, plus Inactive Account Detection and Privilege Escalation Detection.
For operationalizing least-privilege at scale.
Everything in Advanced, plus Remediation Recommendations, Risk Scoring, Governance Review, full Scan History, Scheduled Scans & a headless CLI.
All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.
Standard covers the core of Access Auditor: a full recursive scan of any local path, mapped drive, or mounted share, with Excessive Access Detection flagging broad groups like Everyone or Authenticated Users holding write-capable access. There's no inheritance, orphaned-SID, inactive-account, or privilege-escalation checking at this tier.
Best for: Anyone taking a first look at where access has quietly gotten too broad.
Standard+ adds Broken Inheritance Detection (folders where inheritance has been explicitly disabled) and Orphaned SID Detection (an ACE or owner whose identity no longer resolves to a live account) - the two structural issues that quietly undermine a permission model over time. Everything from Standard is included.
Best for: Teams that need to catch structural drift, not just overly-broad grants.
Advanced adds Inactive Account Detection (accounts that still hold live access but haven't logged in for an extended period) and Privilege Escalation Detection (group-nesting paths where a low-privilege account ends up with far more access than intended). Everything from Standard+ is included.
Best for: Organizations that need to find the risks a plain ACL listing won't show them.
Professional adds least-privilege Remediation Recommendations, a Risk Score per finding, a Governance Review workflow, full Scan History, Scheduled Scans (unattended, recurring audits via Windows Task Scheduler), and a headless CLI (AccessAuditor.exe --scan <folder>) for scripted or Task-Scheduler-driven audits. Everything from Advanced is included.
Best for: Organizations that need to operationalize this - not just find access risk once, but drive it down and keep proving it stays down.
Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.