Choose the object set
Run reports against users, devices, or groups across the configured directory root, or narrow the report to a specific OU when the question is limited to one part of the organization.
HILOP / Capabilities
HILOP combines first-party providers, customer-controlled automation, source-aware administration, reporting, and audit history without pretending every system exposes the same capabilities.
Platform capability
Capability depends on runtime profile, provider health, provider permissions, object type, Microsoft service behavior, and workflow configuration.
| Area | What HILOP provides | Primary sources |
|---|---|---|
| Runtime profiles | Profile selection, cloud choice, provider setup, branding, ProgramData-backed configuration, and provider-specific tooltips. | HILOP profile store |
| Licensing | Activation state, installation tracking, unlicensed search-only behavior, and restricted tools or edits when unlicensed. | Little Innovation Tech licensing service |
| User lookup | Unified selected-user context across directory, Graph, Exchange, groups, direct reports, mailbox, authentication posture, and assigned devices. | AD · Graph · Exchange |
| User administration | ADUC-style editing, attribute editor, manager changes, direct report movement, group picker flows, and source-owned writes. | AD · Graph · Exchange |
| AD Reports | Schema-backed attributes, object-type presets, saved custom reports, OU scoping, result viewing, and CSV export. | AD · Directory Simulator |
| Mailbox operations | Recipient, forwarding, delegation, GAL, and distribution operations where Microsoft exposes supported management surfaces. | Exchange Online / On-Prem PowerShell |
| Devices | Cross-source search, assigned-device matching, Intune sync, LAPS rotation, secret reveal, retire, and source-specific deletion. | AD · Graph · Intune |
| Workflows | JSON-defined forms, validation, confirmation, actions, REST, email, browser launch, delay, approval, conditions, and PowerShell steps. | Native providers · REST · PowerShell |
| Utilities | Hybrid Sync test-and-run workflow with remote PowerShell output displayed in the console. | AD Connect environment |
| Audit | Durable event log with actor, target, provider, before/after values, outcomes, metadata, warnings, errors, and readable detail view. | Local audit journal |
AD Reports
AD Reports gives operators a practical reporting workspace inside HILOP instead of forcing every directory question through ADUC exports, one-off scripts, or external reporting tools.
Run reports against users, devices, or groups across the configured directory root, or narrow the report to a specific OU when the question is limited to one part of the organization.
Selectable report attributes are discovered from the current Active Directory schema, with grouped categories to make large schema sets easier to navigate.
Operators can review results directly in the AD Reports tab, export immediately to CSV, or save reusable custom report definitions under ProgramData.
Device Operations
HILOP combines Active Directory, Entra ID, and Intune device context so operators can move from a user to assigned devices or from a device back to its primary user.
A new search replaces the active search. Shared user and device terms stay synchronized, and SAM-account searches can resolve the matching cloud identity for assigned-device discovery.
BitLocker recovery keys and Windows LAPS passwords remain hidden until the operator chooses the corresponding reveal action and has the required Microsoft Graph permissions.
Operators can request an Intune sync, rotate a Windows LAPS password, retire a managed device, or delete the selected record from Intune, Entra ID, Active Directory, or all applicable sources.
Workflow action model
Workflow definitions can combine identity-native operations with broader automation and explicit execution control.
Operational status
HILOP does not bypass tenant, directory, Exchange, Intune, workstation, or service permissions. It centralizes the experience and routes work through the configured provider path.
See the experience