How to open monitoring for local account audit?

Open the view from the application menu: Menu -> Monitoring -> Audit - accounts. This page does not describe continuous user activity. It describes the daily state of local accounts collected by the agent from a monitored computer. In practice, it is automatic inventory of Windows accounts: it shows Local Users, Enabled Users, Disabled Users, Local Administrators, Service Accounts, account statuses and cases where No Password Required may need administrator review.

Use this view when you want to check whether local administrators have appeared on computers, whether the Guest account or built-in Administrator is enabled, whether local accounts require passwords and whether the account state matches the security policy. Local account audit monitoring is especially useful after deploying new computers, changing user profiles, service work or suspected manual changes on an endpoint.

The view layout consists of the Analytics Panel, a list of daily entries and an area with detailed data. The analytics panel is explained below because, in this view, it is essential to understand that metrics are based on the latest snapshot for each computer in the selected range. In the table, one record means one audit day for one computer. After clicking a record, the application shows the daily snapshot details for the selected device and employee, broken down into local accounts, local administrators and account properties stored by the audit.


Daily table in monitoring Windows account inventory

The table is the first place for a quick review of account state on computers. It should not be read as a sign-in list. A row represents the result of the daily audit: which accounts and account properties the agent saw on the device when the data was collected.

The most important columns answer specific administrative questions:

  • Local Users - how many local accounts were detected in the daily snapshot.
  • Enabled Users - the number of accounts that can be actively used.
  • Disabled Users - accounts that remain in the system but do not provide active access.
  • Local Administrators - the number of accounts with administrative permissions on the computer.
  • No Password Required - a signal that at least one account may work without a password requirement.
  • Service Accounts - accounts recognized as technical accounts or accounts used by services.

The table also includes information about Guest enabled, Built-in Administrator Enabled, Most Common Account Status, Last Full Name, Last Account Status and Last Session State. Search covers the date, agent, computer, Windows user, active hours, Account Status, User Name, Full Name and data stored in JSON details.


Analytics panel in monitoring daily account snapshots

The analytics panel summarizes the selected range, but account audit works differently from event-based panels. If the range contains several days, the system selects the latest record for each computer and builds the current environment picture from it. This lets you see the current account state instead of adding the same accounts again across many days.

In the panel, check mainly:

  • Local Users - the total number of accounts from the latest computer snapshots.
  • Enabled Users and Disabled Users - the proportion of active and inactive local accounts.
  • Local Administrators - the scale of administrative permissions outside a domain or central directory.
  • No Password Required - the number of accounts worth treating as a review priority.
  • Active Sessions and Service Accounts - additional technical context for the device.
  • Computers and Employees - the scope of endpoints and people included in the analysis.

Range modes help you choose the right perspective. Day shows a single snapshot, week or month helps find the last known state for many computers, and a custom range is useful when an audit was run after a larger organizational change.


Rankings in monitoring local accounts and administrators

Rankings organize the data so you can quickly point to computers and account names that need attention. By default, the view focuses on computers because account audit usually starts with one question: on which device does the local permission state look different than expected?

Available summaries include:

  • Local Users - account names visible in the latest snapshots, with additional information about enabled accounts.
  • Local Administrators - computers with the largest number of local administrators.
  • No Password Required - devices where local accounts without a required password were detected.
  • Account Statuses - the distribution between Enabled and Disabled values, calculated from the latest state.
  • Computers and Employees - a view of account counts by devices and assigned users.

It is best to read rankings from the highest-risk categories. A large number of local administrators may indicate an ordinary service computer, but it may also point to leftovers from manual configuration. The No Password Required ranking should lead to a quick account check in the record details.


Trends in monitoring daily account audit changes

Trends show how account counters changed on consecutive days. They are not a timeline of individual operations such as account creation, account enabling or password changes. They are a series of daily states that makes it easier to notice when the number of local users, administrators or accounts with no password required begins to grow.

This tab includes trends for Local Users, Enabled Users, Disabled Users, Local Administrators, No Password Required and Service Accounts. Each chart point represents aggregation of the daily snapshot from computers included in the selected range.

When reading trends, pay attention to jumps between days. If the number of Local Administrators increased after service work, check whether the accounts were removed or disabled after the work ended. If No Password Required is growing, treat it as a signal to audit password policy on specific endpoints.


Comparisons in monitoring local permission state

The comparison tab sets the selected period against a baseline. In the Audit - accounts view, it helps assess whether the current state of local accounts differs from the earlier picture of the environment. This is useful during checks after migration, computer replacement or administrator actions.

The most practical comparison metrics are:

  • Local Users - shows whether the total number of local accounts increased or decreased.
  • Local Administrators - helps detect expanded local permissions.
  • No Password Required - indicates a change in the number of accounts without a password requirement.
  • Enabled Users and Disabled Users - show shifts in account statuses.
  • Service Accounts - help distinguish technical changes from user accounts.

If a comparison shows growth, do not assume an incident immediately. First check whether the change affects many computers or one machine. Then open the details and review User Name, Full Name, Account Status and the Service Account flag.


Anomalies in monitoring risky local accounts

Anomalies in this view focus on states that may weaken computer security. Because the source is a daily snapshot, an alert means a detected account state in the latest audit or a change in administrator count compared with the comparison period.

The panel may point to the following situations:

  • Guest account is enabled - the built-in Guest account appeared as active in the latest account inventory.
  • Built-in Administrator account is enabled - a high-permission account remains active and requires a deliberate decision.
  • Local account does not require a password - at least one local user account works without a password requirement.
  • Local administrator count changed - the current snapshot differs from the baseline period in the number of administrators.

In anomaly evidence, check Guest Account Enabled, Built-in Administrator Enabled, Password Not Required Count, Current Local Administrator Count and Baseline Local Administrator Count. For administrator alerts, always open the record details because that is where the exact account and computer become visible.


Record details in monitoring user audit

After clicking a record, the application shows daily snapshot items for one computer. Details are intended for checking specific accounts, so you will not see a separate sign-in history or a complete session list here. Session data may affect summary counters, but the details table focuses on local accounts and local administrators.

In the details, you will find for example:

  • Item Type, which distinguishes Local user from Local administrator.
  • User Name and Full Name collected from the daily audit.
  • Account Status, which tells whether the account is enabled, disabled or has another recognized state.
  • Password required and Service Account as properties that help assess risk.
  • Active, First Seen, Last Seen and Active Hours, which show the presence frame of the item in the given record.

The best working order is simple: first filter by computer or account name, then check status and password requirement, and finally assess whether the account belongs to the normal endpoint configuration. For technical accounts, compare the name and full name with administrative documentation, because the Service Account flag alone is not always enough for a decision.


Data quality in monitoring local account snapshots

The data quality section tells you whether daily records have details consistent with the summary and whether the range has missing days. For local account audit this matters because the panel builds the current picture from the latest computer snapshot. Missing details may make it harder to determine which exact account is responsible for a counter visible in the table.

Messages may refer to closed records without details, account inventory not matching the daily summary or elapsed days that do not contain audit data. The current day may still be aggregating, so a single warning from today does not have to mean an agent problem.

The Hourly Presence chart has a special meaning in this view: a marked hour means that the account inventory snapshot was collected during that local hour. It is not an hour of account use, sign-in time or user activity. Hourly filtering does not split daily account inventory because the snapshot describes computer state, not a series of events during the day.


Settings for monitoring automatic account audit

Data for the Audit - accounts view depends on monitoring profile settings in the Audit area. The most important editable switch is Automatic Audit. When it is enabled, the agent can collect inventory data used by audit views, including the daily inventory of local accounts.

The profile also shows Users and Sessions Audit, which identifies the data area related to accounts and sessions, but in the current settings panel configuration it is not an editable switch. This distinction matters: the manual describes only options the user can actually change in the interface.

After changing Automatic Audit, give agents time to collect the next daily snapshot. Only after the new cycle should you return to Audit - accounts and check Local Users, Local Administrators, No Password Required, Service Accounts and anomalies related to the Guest account and built-in Administrator.