Know exactly who can touch what - and be able to prove it on demand. NTFS and SMB permission audits made simple.
Permission Reporter generates detailed reports on NTFS and SMB permissions, inheritance, ownership, and access rights across file servers and shares - producing compliance-ready documentation, surfacing excessive permissions, and turning a permission review from a week of manual digging into a single scan. Every audit runs entirely offline: nothing is ever sent to an external service for analysis.
The real app. Click to zoom in, hover the markers to see what each part does.
Hover a marker for details, or click the screenshot to zoom in.
Every access control entry per file/folder - principal, rights, Allow/Deny, and whether it's inherited or explicit - from a full recursive crawl.
The separate share-level ACL that sits on top of NTFS and controls network access to a share - read directly via Windows' own share APIs, the layer most NTFS-only audits miss entirely.
Rule-based, explainable: flags broad groups like Everyone or Authenticated Users holding write-capable access, so risky grants don't stay hidden in a long ACL.
Finds ACEs and owners whose identity no longer resolves to a live account - the classic sign of access left behind by a departed user or deleted group.
Flags folders where inheritance has been disabled - not inherently wrong, but a detached permission chain worth an auditor's own review.
Export CSV compliance documentation, revisit and re-export the full history of every past scan, and set up recurring unattended audits via Windows Task Scheduler.
Pick the depth of audit you need, then choose once-off or monthly billing. Permission Reporter licenses per machine, not by data volume.
One-time payment - yours to keep, no subscription.
For a first look at who has access.
Full recursive NTFS permission crawl reporting every ACE - principal, rights, Allow/Deny, inherited-vs-explicit.
For seeing the whole picture, not just NTFS.
Everything in Standard, plus SMB Share Permissions and Ownership Reports.
For finding what's actually wrong.
Everything in Standard+, plus Excessive Permissions, Orphaned SID, and Broken Inheritance Detection.
For operationalizing compliance at scale.
Everything in Advanced, plus Compliance Report export, full Scan History, Scheduled Scans & a headless CLI.
All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.
Standard covers the core of Permission Reporter: a full recursive crawl of any local path, mapped drive, or mounted share, reporting every NTFS access control entry - principal, rights, Allow/Deny, and whether it's inherited or explicit. There's no SMB share visibility, ownership rollup, or finding detection at this tier.
Best for: Anyone taking a first look at who actually has access to a share or volume.
Standard+ adds SMB Share Permissions - the separate permission layer that sits on top of NTFS and controls network access to a share, which most NTFS-only audits miss entirely - plus Ownership Reports rolling up what each recorded owner controls. Everything from Standard is included.
Best for: Teams that need the whole access picture, not just the NTFS half of it.
Advanced adds Excessive Permissions Detection (broad groups like Everyone/Authenticated Users holding write-capable access), Orphaned SID Detection (an ACE or owner whose identity no longer resolves to a live account), and Broken Inheritance Detection (folders where inheritance has been disabled). Everything from Standard+ is included.
Best for: Organizations that need to find what's actually wrong with a permission structure, not just see a raw list of it.
Professional adds Compliance Report export (CSV) and full Scan History - every scan is logged regardless of tier, so a Professional upgrade has real history to revisit immediately - plus Scheduled Scans (unattended, recurring audits via Windows Task Scheduler) and a headless CLI (PermissionReporter.exe --scan <folder>) for scripted or Task-Scheduler-driven audits. Everything from Advanced is included.
Best for: Organizations that need to operationalize this - not just audit permissions once, but keep proving compliance on an ongoing basis.
Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.