Tools / Free Tools

Prove one thing clearly, then decide if you need a bigger workflow.

Each free item solves a bounded operator job and should be useful on its own. When several assets cover the same operational problem, start with the item marked Primary workflow; supporting utilities handle narrower collection, parsing, or implementation tasks.

47 published tools4 focused collectionsExplore complete products

Choose A Starting Point

Browse by the kind of work

Complete Directory

All free tools

See recent additions

Scripting

Reusable PowerShell and command starters for repeatable admin work, quick checks, and practical automation.

View collection
PowerShell server connectivity quick checkA concise read-only connectivity triage script that separates DNS, ICMP reachability, and expected TCP-port failures before escalation.Connectivity and Network TriageRead-onlyWindows server health snapshotA read-only Windows Server health snapshot that returns one compact row per host for uptime, disk pressure, memory headroom, stopped automatic services, and recent system errors.Windows Server HealthRead-onlyPending reboot detection across Windows serversA read-only pending reboot check for Windows servers before patching, application installs, or maintenance-window closure.Patch and Reboot ReadinessRead-onlyCertificate expiration scannerA read-only certificate inventory that finds local-machine store certificates nearing expiration and captures certificates presented by known TLS endpoints for review.Security and Exposure ChecksRead-onlyIIS site and binding inventoryA read-only IIS inventory that correlates sites, bindings, ports, host headers, app-pool identities, content paths, and certificate thumbprints for migration or renewal work.Windows Server HealthRead-onlyLocal administrator group audit across Windows endpointsA read-only local administrator audit that records privileged group membership across Windows endpoints for review.Active Directory and IdentityRead-onlyFile share permission auditA read-only file share audit that records SMB share permissions, NTFS access, and ownership evidence for review.Supporting utilityFile, Backup, and Storage OperationsRead-onlyWindows firewall rule auditA read-only Windows Firewall audit that records enabled allow rules, ports, profiles, and address scopes.Security and Exposure ChecksRead-onlyDNS resolution and reverse lookup auditA read-only DNS audit that compares forward and reverse lookup results across host lists and expected DNS servers.Connectivity and Network TriageRead-onlyInstalled Application Inventory for Windows EndpointsA read-only PowerShell inventory starter for collecting installed applications from local or remote Windows endpoints.InventoryRead-onlyRDP failure triage scriptA read-only RDP triage script pattern for DNS, TCP 3389, listener state, firewall evidence, sessions, and event logs.Connectivity and Network TriageRead-onlyRobocopy job template and log parserA safer Robocopy job template with dry-run review, log capture, exit-code interpretation, and migration evidence.Supporting utilityFile, Backup, and Storage OperationsReview before runningRobocopy Job TemplateA safer starting point for repeatable Windows file copy jobs with logging and dry-run review.Supporting utilityFile ServicesReview before runningAzure Arc bulk onboarding CSV and logging starterReusable starter for Azure Arc onboarding waves using a host CSV, dry-run expectations, per-host logging, and repeatable result tracking suitable for tickets, change records, and post-wave reporting.Hybrid Cloud OperationsRead-onlyAzure Update Manager patch wave planning templateOperator-ready planning template for Azure Update Manager patch waves covering scope, maintenance windows, reboot tolerance, exclusions, soak periods, rollback contacts, and stop-go criteria before scheduled patching.Hybrid Cloud OperationsRead-onlyAll-DC lastLogon collector and stale-user evidence reportCollect non-replicated lastLogon values from every writable domain controller, calculate the newest observed logon per account, and export evidence suitable for stale-user or stale-computer cleanup decisions without relying on replicated lastLogonTimestamp alone.Active Directory and IdentityRead-onlyAuthenticated Users drive ACL scannerPowerShell scanner that checks fixed local drives on Windows servers for root ACL entries where Authenticated Users have broad access. Produces console and CSV evidence so admins can review exposure before any ACL changes.Security and Exposure ChecksRead-onlyService account usage finderA read-only configuration-discovery pass for service-account assignments in Windows services, scheduled tasks, and IIS application pools, designed as the first step of—not a substitute for—the full retirement evidence workflow.Supporting utilityActive Directory and IdentityRead-only

Reporting

Foundations, helpers, templates, and report-oriented tools for turning raw checks into repeatable operator evidence.

View collection
Disk space cleanup candidate reportA read-only disk-pressure report that captures low-space context and returns targeted cleanup candidates from known folders without deleting, compressing, or moving anything.Windows Server HealthRead-onlyScheduled task inventory and failure reportA read-only scheduled task inventory that highlights failed runs, missed runs, disabled tasks, and ownership gaps.Windows Server HealthRead-onlyDHCP scope utilization reportA read-only DHCP scope report that surfaces high utilization, exhausted ranges, and cleanup candidates.Connectivity and Network TriageRead-onlyAD stale computer cleanup reportA read-only Active Directory stale computer report for last logon, OU, operating system, enabled state, and cleanup planning.Active Directory and IdentityRead-onlyIncident Note TemplateA compact operator note format for capturing symptoms, checks, decisions, and follow-up while the issue is fresh.Operations TemplatesPlanning aidAzure Update Manager compliance workbook starterStarter template for an Azure Workbook plus Resource Graph evidence pack that shows patch compliance, pending updates, unsupported coverage, and patch-group drift across Azure and Arc-enabled machines.Reporting and Evidence PacksRead-onlyRADIUS and NPS server detection reportRead-only PowerShell reporting script pattern to identify likely Microsoft NPS or other RADIUS-capable Windows servers using multiple evidence sources: NPS service presence, NPAS role/feature state, IAS/NPS event log activity, UDP 1812/1813 listener evidence, and registry indicators. Designed for migration discovery, audit support, and authentication troubleshooting.InventoryRead-onlyPowerShell operations reporting foundationUse the Ops Reporting Foundation helper to turn PowerShell checks into consistent HTML, CSV, JSON, and log artifacts. Start here after creating the helper file, then plug health checks, patch checks, certificate scans, AD hygiene checks, and other collectors into the same reporting pattern.Reporting and Evidence PacksReview before runningBuild the Ops Reporting Foundation HelperCreate the local PowerShell helper file that every Ops Stack reporting-compatible script can share. This guide walks through the folder structure, the helper contract, the commented PowerShell implementation, a sample validation run, and the artifacts the helper creates so a new reader can build it from scratch and prove it works.Supporting utilityReporting and Evidence PacksChanges system statePowerShell HTML operations report starterConcrete PowerShell reporting pattern for turning host-check results into an HTML operations summary with a status rollup, per-host table, failure section, saved local artifacts, and optional email delivery.Supporting utilityReporting and Evidence PacksChanges system statePatch compliance Prove the Number monthly evidence packA ready-to-fill monthly record that turns patch-compliance methodology into a defensible reporting package: population reconciliation, denominator rules, unknown/stale systems, exclusions, applicability, evidence coverage, exceptions, signoff, and management summary.Primary workflowReporting and Evidence PacksPlanning aid

Apps

Built-in and third-party utilities worth keeping around when the workflow is better served by a purpose-built tool.

View collection

Guided Drills

Step-by-step validation drills for backup restores, access checks, readiness checks, and other proof work.

View collection
RDP Connectivity ChecklistA structured check for RDP failures before changing firewall rules, user rights, or server policy.Remote AccessRead-onlyBackup Restore Drill Evidence ChecklistA restore-drill evidence template for proving backups are usable, measuring recovery time, and turning failed assumptions into repair tasks before an outage.Supporting utilityBackup and RecoveryChanges system stateWindows Update Repair ChecksA staged Windows Update troubleshooting path that starts read-only and escalates only when needed.Supporting utilityPatchingReview before runningWindows Update readiness and repair evidence packA patch readiness and repair evidence pack for reboot state, servicing health, update logs, and approved repair actions.Supporting utilityPatch and Reboot ReadinessChanges system stateAzure Arc onboarding preflight checklistPreflight checklist for onboarding Windows servers to Azure Arc. Confirms supported OS state, outbound connectivity, proxy/TLS behavior, local admin rights, target Azure placement, tagging, pilot scope, and rollback notes before any agent install.Hybrid Cloud OperationsRead-onlyInactive AD user disable review workflowTwo-phase review checklist for identifying inactive AD user accounts, validating inactivity evidence, applying exclusions, capturing approval, and preparing rollback details before any disable action.Active Directory and IdentityChanges system stateInternal IIS site rollout checklistOperator checklist for launching an internal IIS-hosted site with evidence capture for IIS role presence, site folder layout, bindings, app pool identity, DNS readiness, browser validation, and rollback notes.Application HostingRead-onlyDNS and DHCP Health CheckA read-only two-client DNS failure workflow that collects the same evidence on the affected and known-good Windows clients, compares suffix, resolver, cache, and query paths side by side, and narrows the first actual delta before any reset.Primary workflowDNS and DHCPRead-onlySMB working-user vs failing-user access comparisonCompare a working and failing user's identity, token, Kerberos, share ACL, NTFS ACL, inheritance, and effective-access path to identify the first authorization delta before changing permissions.Primary workflowActive Directory and IdentityRead-onlyWindows Server update failure evidence-first runbookA Windows Server-specific observe, compare, repair, validate workflow for one server that fails a monthly update while a peer succeeds, with proxy, update-source, servicing, applicability, CBS/DISM, and before/after evidence.Primary workflowPatch and Reboot ReadinessChanges system stateService account retirement evidence workflowCombine configuration discovery with runtime authentication evidence, SPN/Kerberos review, owner approval, an observation window, and explicit DISABLE / HOLD / ROLLBACK criteria before retiring a domain service account.Primary workflowActive Directory and IdentityChanges system stateInternal URL monitoring deployment and trust runbookOne authoritative path for monitoring 10–20 internal HTTP/HTTPS endpoints: define endpoint semantics, deploy Uptime Kuma, set retry and maintenance policy, add TLS/auth checks, alert, retain history, and prove the monitor with a controlled outage.Primary workflowMonitoring and ObservabilityPlanning aidPrimary workflow: Robocopy migration cutover evidence packThe primary production file-migration workflow: plan, dry-run, pre-seed, freeze writes, final delta, validate data/metadata/access, and make an explicit GO / STOP / ROLLBACK decision before the destination becomes authoritative.Primary workflowMigration and CutoverChanges system stateBackup restore drill evidence recordA ready-to-fill restore-test record with scope, isolated restore evidence, application/data validation, measured RPO/RTO, failures, assumptions, cleanup, owner signoff, and a management/change summary.Primary workflowBackup and RecoveryPlanning aid

Disclosure: Some future recommendations may use affiliate links where available. Recommendations should stay practical, clearly labeled, and tied to operator use cases.