Skip to Main Content
Liongard Library

Welcome to Liongard Library, where Lions share! This is a community-led space where Liongard users can come to teach and learn from one another.
Share custom Metrics, get inspired and see what’s trending in the Pride.

Pride Etiquette:
➕ Have great custom Metrics? Add them as entries!
🌟 Want to use a Metric? Copy the query and
follow this doc.
👍 Tried a Metric from the Library? Like it!
📣 Have a question or feedback on a Metric? Add a comment!
🔎 Not sure where to start? Learn about Metrics and how to write them.
💬 Need help writing a metric or want to help support others? Join the conversation in our Liongard Lounge #metrics slack channel.


🥴 See something off? Open a support chat to let us know.

ADD A NEW METRIC ENTRY

Active Directory

Showing 104 of 917

Active Directory: Software Restriction Policy Checker

We have several techs at our MSP that will turn off the entire SRP to install a blocked application. Obviously this is a no-no and should be avoided but with this Liongard metric you can create a simple rule to see if the policy has been disabled....
Ryan Wooff almost 2 years ago in Active Directory 0

Active Directory: FSMO Role Holders List v2

Tweak to default FSMO role holders - includes which servers hold which role
Austin B [QuoStar] about 2 years ago in Active Directory 0

Active Directory: Computers Details [PowerBI]

Returns the name, ip address, os system, os version, and last password set date of each device in Active Directory.
Guest over 2 years ago in Active Directory 0

Active Directory: Check LDAP Channel Binding Policy

Check group policy to confirm if LDAP channel binding is enabled to mitigate known vulnerabilities. https://msrc.microsoft.com/update-guide/en-us/vulnerability/ADV190023 https://support.microsoft.com/en-us/topic/2020-ldap-channel-binding-and-l...
Lee Mackie over 2 years ago in Active Directory 0

Active Directory: Check LDAP Signing Policy

Check LDAP Signing is enabled via Group Policy to ensure mitigation of known vulnerabilities. https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/domain-controller-ldap-server-signing-requirements To ...
Lee Mackie over 2 years ago in Active Directory 0

Active Directory: Current Time

Use this metric to find where agents are not pulling Active Directory data correctly or are failing. Using this metric, I found it is a good idea to use our RMM to restart the liongard service every day.
Jason Holcomb over 2 years ago in Active Directory 0

Active Directory: KRBTGT Account Password Needs Reset

krbtgt user account password should be changed at a minimum every 180 days. https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/ad-forest-recovery-resetting-the-krbtgt-password
matt longenecker over 3 years ago in Active Directory 0

Active Directory: User Accounts With Brute Force Attempts Count 5+ Count

Current Brute force metric alerts after 4 failed attempts even on disabled accounts from multiple years ago. This provides a custom option to be closer to the lockout policy with the option of monitoring only enabled accounts. This provides a coun...
Devon over 3 years ago in Active Directory 1

Active Directory: Display Names of DNS Forward Lookup Zones

This can be useful if needing all forward lookup zones for DNS filtering platforms such as Cisco Umbrella where all lookup zones need to be accounted for.
Nick Dechnik over 3 years ago in Active Directory 0

Active Directory: Count of DHCP Scopes with Failover Configured

Will count the number of DHCP scopes that have DHCP failover configured for them. Can combine with a total count of DHCP scopes metric to determine if there are scopes without failover enabled.
Robbie Kibler over 3 years ago in Active Directory 0