Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Audit Active Directory groups by combining a dated inventory of membership and group metadata with owner review and dependency checks. An empty group, an old change date, or a quiet log is a reason to investigate—not proof that a group is unused. Microsoft’s cleanup guidance uses staged “scream tests” to validate candidate groups before removal.

1. Define the audit scope and capture a baseline

Start by recording which domain and organizational units (OUs) are in scope, when the data was collected, and which domain controller answered the query. Decide whether the review includes security groups, distribution groups, or both. Preserve stable identifiers such as distinguished name (DN) and security identifier (SID), where available, along with group scope, category, members, and relevant metadata.

Get-ADGroup can retrieve a group by DN, GUID, SID, or SAM account name, or search using -Filter or -LDAPFilter. Use -SearchBase to limit a search to an OU and request properties you need, such as member. See Microsoft’s Get-ADGroup reference for the supported parameters. Run queries with suitable permissions; insufficient directory-level permissions can cause a terminating error.

2. Review membership by object type

Inspect members as directory objects rather than counting only users. Different object types suggest different validation paths, but none independently proves whether a group is needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Computers: may indicate Group Policy or System Center administration dependencies.
  • Contacts or identities excluded from Entra synchronization: require context-specific investigation rather than an assumption that they are obsolete.
  • Users or groups synchronized to Microsoft Entra: should prompt checks for cloud use as well as on-premises dependencies.
  • No members: merits investigation, but Microsoft’s cleanup workflow still proceeds to usage checks for empty groups.

Microsoft’s AD DS group cleanup guidance discusses these member types as triage clues, not deletion criteria.

3. Add ownership and change context

Compare creation and change information with the group’s accountable owner and records for applications, servers, scheduled jobs, Group Policy objects, and service accounts. An old date can help prioritize review, but the Microsoft cleanup guidance does not establish a universal age or inactivity cutoff that proves a group is unused.

Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

Ask an owner or technical contact what the group grants, which systems consume it, and whether its members still need that access. Record the decision and supporting context. If there is no known owner, treat that as a governance issue to resolve—not evidence that the group is safe to delete.

4. Validate candidate groups with staged dependency checks

Microsoft describes a “scream test” as temporarily making a potentially unnecessary resource unavailable and waiting to see whether anyone reports an impact. For group cleanup, its guidance calls for staged checks covering cloud, Kerberos, and LDAP usage. This is a controlled validation method, not a guarantee that every dependency will be detected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check cloud usage: for synchronized groups, determine whether Entra applications or services depend on the group.
  2. Check Kerberos and LDAP usage: investigate application and infrastructure dependencies that consume the group or its membership.
  3. Coordinate the test: agree on the candidate, scope, monitoring window, communications, and rollback plan with service owners before changing availability.
  4. Observe and record: track reports and technical evidence during a window appropriate to workload cycles. Microsoft does not prescribe one duration that fits every environment.
  5. Decide deliberately: retain, revise, or remove the group only after the evidence and accountable owner decision are reviewed.

Because temporarily disabling access can disrupt services, apply local change control and recovery procedures. A quiet test window alone cannot establish non-use across all application schedules or business cycles.

5. Use membership reviews for people decisions

Microsoft Entra access reviews can support recurring membership attestations. Microsoft recommends regular reviews and notes that group owners are often well placed to decide who still needs access. For groups synchronized from on-premises AD, choose reviewers who understand the AD group: synchronized groups cannot have an Entra owner.

Access-review results can inform remediation, but they do not directly edit the membership of groups synchronized from AD. On-premises AD remains the source of authority, so administrators must apply approved membership decisions there. Review the Microsoft Entra access-review planning guidance for the hybrid workflow. Completed decisions can be downloaded or retrieved programmatically for action in AD.

6. Keep the evidence types distinct

Inventory, change logs, and Windows logon-token auditing answer different questions. None is complete usage telemetry on its own.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Evidence What it can show What it does not establish
AD directory inventory Current group properties and membership within the query’s scope. Whether a dependent application or service actually uses the group.
Entra directory audit logs Recorded Entra directory changes, including group-management activity such as adding a member. Complete on-premises AD change history or all runtime dependencies.
Windows Audit Group Membership Group information present in a user’s logon token on the computer where the session is created. Whether every group was used by every service or resource.

Microsoft’s Get-EntraAuditDirectoryLog documentation covers Entra directory audit data and demonstrates filtering for “Add member to group.” The documentation describes supported roles and the AuditLog.Read.All and Directory.Read.All scopes in its examples. This is Entra audit data, not a replacement for on-premises AD change auditing.

Windows Audit Group Membership records group information included in a logon token. Audit Logon must also be enabled. Interactive logon events are generated on the logon computer; network logon events are generated on the computer hosting the resource. Use these events as scoped observations, not as proof that a group is or is not used everywhere.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

7. Preserve a review trail and make changes at the authority

For each reviewed group, retain the before snapshot, evidence considered, named owner decision, approvals, change record, and after snapshot. For AD-sourced synchronized groups, implement approved changes in on-premises AD, then verify the resulting state through your normal synchronization and validation process.

A clear record makes future reviews more reliable: it shows why a group was retained or removed, which dependencies were considered, and who approved the outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.