BeyondInsight Reporting in AD Bridge

The AD Bridge GPO, User Monitor, sends the following data to the BTEventDBReaper service that then forwards the data to BeyondInsight:

  • Users that are added, deleted, or changed.
  • If the user has the Allow Logon rights GPO set, then changes and deletions are recorded.

No historical data is retained in the BeyondInsight database. Data is overwritten when new updates are sent to the BeyondInsight database.


  • On the domain controller, turn on User Monitor.
  • If running an earlier version of User Monitor, you must upgrade the BTEventDBReaper service before upgrading User Monitor.
  • After BTEventDBReaper is upgraded, you can upgrade the agent. If the BTEventDBReaper service is not updated first, it cannot process the records from the agent which will result in a failure of processing data.
  • Allow Logon Rights must be turned on and configured for users and groups that you want to log into the agents.

If Allow Logon Rights is not configured, the BeyondInsight report will show a single record for All Users. To populate the report with individual users, Allow Logon Rights must be set.

  • AD Bridge Enterprise collectors must be installed.

For more information, please see Install the Collectors with the Database Utilities Package.

  • BeyondInsight 6.2 or later.

Generate a Certificate

Generate a client certificate using the BeyondInsight Configuration tool. A certificate must be created and copied to the AD Bridge server certificate store to ensure secure communications.

To generate a certificate:

  1. Run the configuration tool, and then click Certificate Management.
  2. Select Generate Certificate, and then select Client Certificate from the Certificate type menu.
  3. Enter a password.
  4. Click OK.

Copy the Certificate to the AD Bridge Enterprise Server

An image of the location of the Import menu option in the MMC Certificates Snap-in.

  1. Log into the AD Bridge Enterprise server, open MMC and add the Certificates Snap-in for the Local Computer account.
  2. Expand Certificates (Local Computer).
  3. Right-click Trusted Root Certificates > All Tasks > Import.
  4. Import the certificates created using the BeyondInsight Configuration tool.


  1. Move the client certificate (eEyeCmsClient) to the Personal certificates store.

Run the DBUtilities Tool

You must establish a connection to the BeyondInsight server.

To run the DBUtilities tool:

An image of Reporting Database Connection Manager in the Start menu.

  1. From the Start menu, select Reporting Database Connection Manager. You must run the connection manager as Administrator. Right-click the menu item, and then select Run as administrator.
    • Alternatively, you can also run the tool from the command line:
    • bteventdbreaper /gui


  1. Select the Enable BeyondInsight check box.
  2. Enter the URL to the BeyondInsightserver.
  3. Enter the name of the client certificate generated earlier.

An image of a Reporting Database Connection screen configuration example.

  1. Optionally, create a workgroup name. A workgroup name can be used as a unique identifier.


  1. Click Test Connection to ensure the connection between the servers is successfully established.
  2. Click OK.

View Reports in BeyondInsight Analytics and Reporting

  1. Log into Analytics and Reporting.
  2. Select View All Reports from the menu.

An image location of AD Bridge on the BeyondInsight Analytics and Reporting screen.

  1. Select AD Bridge.


  1. Select a report.

An image of Configure Report on the BeyondInsight Analytics and Reporting screen.

  1. Enter the report parameters, and then click View Report.