---
title: Windows Audit Report
slug: kronpam-reference-guide-3-5-0/windows-audit-report
description: Learn how to create and run a Windows Local User Audit Report with this step-by-step guide. Customize your report configuration, exclude service accounts, and choose between manual or scheduled execution. Easily access and view the report details in the W
docTags: 
createdAt: 2022-08-02T08:54:47.000Z
---

The Windows Local User Audit Report is used to report the current security status of local Windows accounts.

Create the Report Configuration

1. Navigate t&#x6F;**&#x20;Audit Report** >**&#x20;Windows Audit Report**.
2. Open the **Report Configuration** tab.
3. Create the report configuration by completing the fields. The Report job can be executed manually or periodically (as scheduled)
4. We have the parameter **Exclude Service Accounts** which we can enable on the Device Group. If that parameter is enabled on the Device Group then it excludes all those users to fetch in the Windows audit report. When we execute the audit report, we enable this highlighted parameter.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/LnfjpAdQ3JTCmwOI5X18G_image.png "Windows Audit Report Configuration")

To execute the report manually, click the **Options&#x20;**&#x70;op-up menu button and select **Run**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/iBUgIeJ1tU_kGTHX6qcaZ_image.png "Run Windows Audit Report")

To execute the Reports periodically, the Scheduled field needs to be configured in the Report Configuration. The period can also be configured from the Jobs Scheduler by editing th&#x65;**&#x20;WindowsAuditJob**.

:::hint{type="info"}
For the Audit Report, the selected device groups must have the globalUsername and globalPassword properties defined. See also section Device Group Properties. To be able to access the report detail, the user defined as **globalUsername&#x20;**&#x73;hould be a privileged user.
:::



**Report Details**

When a job finishes, the reports are listed in the Reports tab. To access the report:

1. Navigate to **Audit Report** > **Windows Audit Report**.
2. Open the **Report** tab.
3. Click the **Options** drop-down menu button and selec&#x74;**&#x20;Show Details**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/BZxW6FX1sUMqvC8FOaNwx_image.png "Windows Audit Report")

Report details are shown in the Windows Audit Report Details section:

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/Cppm8OkvKFR9F0duJo0vW_image.png "Windows Audit Report Details")

**Dashboard**

1. Navigate to **Audit Report** > **Windows Audit Report**.
2. Open the **Dashboard** tab.
3. Choose the desired fields and click the **Display Reports** button.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/vbolWI4e_Th6pFGwuC37z_image.png "Windows Audit Report Dashboard")

