AD FastReporter includes a large set of built-in fields organized into categories. This page provides a reference of all field categories with descriptions and example fields. You can see the full field list with descriptions and LDAP attribute names in the application itself — select any report form and browse the Available Fields panel.
Fields marked (Pro) are only available in the Pro edition. Fields marked (Calculated) are computed by AD FastReporter from raw AD data rather than read directly from a single attribute.
Core identification fields available for most object types.
| Example fields | LDAP attribute |
|---|---|
| Name | name |
| Display Name | displayName |
| Logon Name (sAMAccountName) | sAMAccountName |
| User Principal Name | userPrincipalName |
| Distinguished Name | distinguishedName |
| Canonical Name (Calculated) | derived from DN |
| SID | objectSid |
| GUID | objectGUID |
| Description | description |
Available in: Users, Computers, Groups, Exchange, Contacts, Printers, GPOs, OUs.
Physical address attributes from the user’s AD profile.
| Example fields | LDAP attribute |
|---|---|
| Street Address | streetAddress |
| City | l |
| State/Province | st |
| Postal Code | postalCode |
| Country | co |
| P.O. Box | postOfficeBox |
Available in: Users, Contacts.
Organizational hierarchy and company information.
| Example fields | LDAP attribute |
|---|---|
| Company | company |
| Department | department |
| Title | title |
| Manager | manager |
| Manager Description (Calculated) | resolved from manager DN |
| Manager Account Type (Calculated) | resolved from manager DN |
| Managed Accounts (Calculated) | reverse lookup of manager |
| Managed Account Count (Calculated) | count of managed objects |
| Direct Reports | directReports |
Available in: Users, Contacts.
Phone numbers, email, and communication details.
| Example fields | LDAP attribute |
|---|---|
| Email Address | mail |
| Telephone Number | telephoneNumber |
| Mobile | mobile |
| Fax Number | facsimileTelephoneNumber |
| Home Phone | homePhone |
| IP Phone | ipPhone |
| Web Page | wWWHomePage |
Available in: Users, Contacts.
What groups a user, computer, or other object belongs to. These fields answer: “What groups is this object a member of?”
| Field | Description |
|---|---|
| Member Of (Direct) | Groups the object is a direct member of |
| Member Of (Inherited) (Calculated, Pro) | Groups inherited through nested group chains |
| Member Of (All) (Calculated, Pro) | Direct + inherited combined |
| Member Of (Security) (Calculated, Pro) | Only security group memberships |
| Member Of (Distribution) (Calculated, Pro) | Only distribution group memberships |
| Member Of (Domain Local) (Calculated, Pro) | Only domain local scope groups |
| Member Of (Global) (Calculated, Pro) | Only global scope groups |
| Member Of (Universal) (Calculated, Pro) | Only universal scope groups |
| Group Membership Count (Calculated) | Total number of direct group memberships |
| Has Group Memberships (Calculated) | True/False — whether the object has any memberships |
| Primary Group | primaryGroupID (resolved to group name) |
Available in: Users, Computers.
Who is in a group. These fields answer: “What members does this group contain?”
| Field | Description |
|---|---|
| Members (Direct) | Direct members of the group |
| Members (Inherited) (Calculated, Pro) | Members through nested groups |
| Members (All) (Calculated, Pro) | Direct + inherited combined |
| Members Count (Direct) (Calculated) | Count of direct members |
| Members Count (All) (Calculated, Pro) | Count including nested members |
| Has External Members (Calculated) | Whether any members are from other domains |
| Group Scope (Calculated) | Domain Local, Global, or Universal |
Available in: Groups.
User Account Control (UAC) flags and account state. Each flag is exposed as a separate True/False field.
| Example fields | UAC flag |
|---|---|
| Account Disabled | ACCOUNTDISABLE |
| Account Locked Out | LOCKOUT |
| Password Not Required | PASSWD_NOTREQD |
| Password Can’t Change | PASSWD_CANT_CHANGE |
| Password Never Expires | DONT_EXPIRE_PASSWD |
| Smart Card Required | SMARTCARD_REQUIRED |
| Trusted for Delegation | TRUSTED_FOR_DELEGATION |
| Not Delegated | NOT_DELEGATED |
| DES Key Only | USE_DES_KEY_ONLY |
| Preauth Not Required | DONT_REQUIRE_PREAUTH |
| Password Expired | PASSWORD_EXPIRED |
| Encrypted Text Password Allowed | ENCRYPTED_TEXT_PASSWORD_ALLOWED |
| Account Never Expires (Calculated) | derived from accountExpires |
| Protected from Deletion (Calculated) | derived from systemFlags |
| Is Domain Controller (Calculated) | true if DC account |
| Is Domain User (Calculated) | true if primary group is Domain Users |
| Is Domain Guest (Calculated) | true if primary group is Domain Guests |
Available in: Users, Computers (subset).
Password-related dates, policies, and calculated expiration.
| Example fields | Source |
|---|---|
| Password Last Set | pwdLastSet |
| Password Expiration Date (Calculated) | computed from pwdLastSet + domain policy |
| Account Expiry Days (Calculated) | days until accountExpires |
| Account Expires | accountExpires |
| Must Change Password at Next Logon (Calculated) | true if pwdLastSet = 0 |
Available in: Users.
Logon activity and authentication history.
| Example fields | Source |
|---|---|
| Last Logon (Calculated) | lastLogon queried from all DCs — most recent value |
| Last Logon Timestamp | lastLogonTimestamp (replicated, up to 14-day delay) |
| Last Logon DC (Calculated) | which DC recorded the most recent lastLogon |
| Bad Password Time | badPasswordTime |
| Bad Password Count | badPwdCount |
| Days Since Last Logon (Calculated, Pro) | calculated from last logon date |
| Logon Count | logonCount |
Available in: Users, Computers.
User profile, home directory, and logon script settings.
| Example fields | LDAP attribute |
|---|---|
| Home Directory | homeDirectory |
| Home Drive | homeDrive |
| Logon Script | scriptPath |
| Profile Path | profilePath |
Available in: Users.
Remote Desktop Services profile settings.
| Example fields | Source |
|---|---|
| TS/RDS Profile Path | TerminalServicesProfilePath (UserParameters) |
| TS/RDS Home Folder | TerminalServicesHomeDirectory (UserParameters) |
Available in: Users.
Information about where the object is located in the AD hierarchy.
| Field | Description |
|---|---|
| Parent OU | The immediate parent OU name |
| Parent Container | Full container path |
| Parent Container (Reverse) | Container path in reverse order (top-down) |
| Parent Name | Simple name of the parent object |
Available in: Users, Computers, Groups, OUs.
Core Exchange mailbox attributes (requires Exchange schema extensions).
| Example fields | LDAP attribute |
|---|---|
| Exchange Server | msExchHomeServerName |
| Recipient Type Details | msExchRecipientTypeDetails |
| Recipient Display Type | msExchRecipientDisplayType |
| Exchange Object Type (Calculated) | derived from recipient type |
| Alternate Recipient | altRecipient |
| Accept Messages from Everyone (Calculated) | derived from delivery restrictions |
Available in: Exchange (Users, Contacts, Groups).
Protocol access and policy settings for Exchange mailboxes.
| Field | Description |
|---|---|
| OWA Enabled (Calculated) | Outlook Web Access status |
| POP3 Enabled (Calculated) | POP3 protocol status |
| IMAP4 Enabled (Calculated) | IMAP4 protocol status |
| MAPI Enabled (Calculated) | MAPI protocol status |
| OMA State | Mobile device access status |
| Policies Excluded | msExchPoliciesExcluded |
Available in: Exchange.
Exchange mailbox storage quota settings.
Available in: Exchange.
Exchange delivery restrictions and forwarding.
Available in: Exchange.
Published printer attributes.
| Example fields | LDAP attribute |
|---|---|
| Printer Name | printerName |
| Server Name | serverName |
| Share Name | printShareName |
| Location | location |
Available in: Printers.
Group Policy Object attributes.
| Example fields | Source |
|---|---|
| GPO Name | displayName |
| GPO Status (Calculated) | Enabled / User Disabled / Computer Disabled / Disabled |
| Linked Objects (Calculated) | All OUs/sites/domains where the GPO is linked |
| Linked Sites (Calculated) | Sites with this GPO linked |
| Linked OUs (Calculated) | OUs with this GPO linked |
| Linked Domain (Calculated) | Domain-level GPO link |
| Has GPO Linked (Calculated) | For OUs: whether any GPO is linked |
Available in: GPOs, OUs (for link-related fields).
Calculated counts of objects within each organizational unit.
| Field | Description |
|---|---|
| Child Count (Calculated) | Total child objects |
| Child User Count (Calculated) | Number of user objects |
| Child Computer Count (Calculated) | Number of computer objects |
| Child Group Count (Calculated) | Number of group objects |
Available in: OUs.
BitLocker encryption recovery information stored in AD.
| Field | Source |
|---|---|
| BitLocker Password ID (Calculated) | from msFVE-RecoveryPassword child objects |
| BitLocker Recovery Key (Calculated) | from msFVE-RecoveryPassword child objects |
| BitLocker Volume Name (Calculated) | from msFVE-RecoveryPassword child objects |
Available in: Computers. Requires read access to msFVE-RecoveryPassword objects.
Specialized fields for EU NIS2 Directive compliance reporting.
| Field | Description |
|---|---|
| Days Since Last Logon (Calculated, Pro) | Number of days since last authentication |
| Has Admin Privileges (Calculated, Pro) | Whether the account is in administrative groups |
| NIS2 Review Required (Calculated, Pro) | Flags accounts requiring mandatory compliance review |
Available in: Users.
Network address fields for computer objects.
| Field | LDAP attribute |
|---|---|
| IPv4 Address | derived from DNS records |
| IPv6 Address | derived from DNS records |
Available in: Computers.
Remote access dial-in settings.
| Field | Description |
|---|---|
| Dial-In Permission (Calculated) | Allow Access / Deny Access / Control via NPS Policy |
Available in: Users.
Low-level system attributes available for all object types.
| Example fields | LDAP attribute |
|---|---|
| When Created | whenCreated |
| When Changed | whenChanged |
| Object Class | objectClass |
| User Account Control (raw) | userAccountControl |
| SAM Account Type | sAMAccountType |
| Has Photo (Calculated) | checks if thumbnailPhoto exists |
Available in: All categories.
Any LDAP attribute you add through the custom fields feature. These appear in the Custom category in the field list and can be assigned to any report category.
Skype for Business / Lync attributes (if the schema extensions are present in your environment).
Available in: Users.
This reference covers field categories and representative fields. The complete field list — with exact display names, LDAP attribute names, descriptions, and which report categories each field belongs to — is browsable in the AD FastReporter application under any report form’s Available Fields panel. You can also see all fields in Settings → Fields.