Windows OS Hub
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux

 Windows OS Hub / Active Directory / Install Active Directory Users & Computers (ADUC) on Windows

December 22, 2025

Install Active Directory Users & Computers (ADUC) on Windows

The Active Directory Users and Computers (ADUC) snap-in is one of the most commonly used graphical consoles for managing Active Directory domain objects, such as users, computers, groups, organizational units (OU) and permissions. The Active Directory MMC snap-in (dsa.msc) can be installed on both Windows Server hosts and Windows 11/10 workstations.

The ADUC console is part of the Remote Server Administration Tools (RSAT), used to remotely manage Windows Server roles and features, and is installed by default only on Active Directory domain controllers. This article explains how to install and use the Active Directory Users & Computers (ADUC) management snap-in from any Windows workstation.

Contents:
  • How to Install Active Directory Users & Computers on Windows 11 and 10
  • Install Active Directory (ADUC) Console via PowerShell
  • Installing Active Directory Users & Computers Snap-in on Windows Server
  • Working with the Active Directory Users and Computers (ADUC) Console
  • Using the ADUC Console from a Non-domain Computer

How to Install Active Directory Users & Computers on Windows 11 and 10

The Active Directory console is available for Windows 11 and 10 workstations as part of the Remote Server Administration Tools (RSAT). This component is not installed by default in Windows and can be added as a Feature on Demand (FoD) via the Settings -> System -> Optional Features -> View Features. Check the RSAT: Active Directory Domain Services and Lightweight Directory Services Tool in the list and click Add.

Install Active Directory Users and Computers RSAT tools via Optional Features in Windows 11

Windows will connect to Microsoft servers to download and install the Active Directory Remote Server Administration Tools (including Active Directory graphical consoles, command prompt tools, and Active Directory PowerShell module).

Before the release of Windows 10 version 1809, the RSAT components were not included in the system image as ‘Features on Demand’. Instead, they required the installation of a separate MSU update (KB269364). Below are the links to download RSAT for previous Windows versions:

  • RSAT for Windows 10 1803/1709 — https://www.microsoft.com/en-us/download/details.aspx?id=45520
  • RSAT for Windows 8.1 — https://www.microsoft.com/en-us/download/details.aspx?id=39296

download rsat msu package for windows 10

Download the RSAT version that matches your operating system’s bitness. Double-click the MSU file to start installation:

install rsat msu package on windows 10 using standalone installer

Or install the MSU file from the command prompt in quiet mode:

wusa.exe C:\Install\WindowsTH-RSAT_TP5_Update-x64.msu /quiet /norestart

Once the RSAT installation is complete, restart your computer. Next, activate the AD management tools in RSAT:

  1. Open the Turn Windows features on or off dialog by running the optionalfeatures.exe command
  2. Expand Remote Server Administration Tools-> Role Administration Tools -> AD DS and AD LDS Tools in the features tree
  3. Check AD DS Tools and click OK.install ad ds tools in windows features

Install Active Directory (ADUC) Console via PowerShell

In my opinion, it is much easier and faster to install a set of AD management tools on Windows 11 using PowerShell. Check whether the AD tools are installed on a computer.

Get-WindowsCapability -Online -Name Rsat.ActiveDirectory*

If the component is missing (NotPresent), add it using the following command:

Get-WindowsCapability -Online -Name Rsat.ActiveDirectory*|Add-WindowsCapability -Online

Add-WindowsCapability Rsat.ActiveDirectory

In Windows 11, the RSAT.ActiveDirectory optional feature is downloaded from Microsoft servers over the internet. If your computer is on an isolated network or direct internet access is blocked, installing RSAT features will fail with error 0x800f0954.

Active Directory RSAT install error 0x800f0954

In this case, download an offline ISO image containing the Windows Feature on Demand components for your version of Windows from the Microsoft website.

For Windows 11 25H2, I downloaded the ISO (about 6 GB) image Languages and Optional Features for Windows 11, version 24H2 and 25H2 (contains language packs for Windows and Features on Demand).

Download FoD ISO image for Windows 11

Mount the downloaded FoD ISO image on the workstation and run the offline installation of the AD management tools from it.

Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0 -LimitAccess -Source D:\LanguagesAndOptionalFeatures\

PowerShell: offline installation Active Directrory DSA.msc snapin

Or you can manually inject features from the CAB file Microsoft-Windows-ActiveDirectory-DS-LDS-Tools-FoD-Package~31bf3856ad364e35~amd64~en-US~.cab into the Windows image using DISM.

If you are installing Active Directory consoles on computers that receive updates from a corporate WSUS server, you must apply the ‘Specify settings for optional component installation and component repair‘ GPO to them with the Download repair content and optional features directly from Windows Updates instead of Windows Server Updates Services (WSUS) option enabled. In this case, instead of trying to retrieve Features on Demand components from the intranet WSUS server, the Windows computer will contact Microsoft’s servers directly via the internet.

GPO: download FoD from WindowsUpdate instead WSUS

Before Windows 10 build 1809, it was possible to install the ADUC snap-in using DISM from the command prompt as well:

dism /online /enable-feature /featurename:RSATClient-Roles-AD
dism /online /enable-feature /featurename:RSATClient-Roles-AD-DS
dism /online /enable-feature /featurename:RSATClient-Roles-AD-DS-SnapIns

install RSATClient-Roles-AD-DS-SnapIns features

Installing Active Directory Users & Computers Snap-in on Windows Server

The ADUC console and other Active Directory administration tools are installed automatically on a Windows Server host when the ADDS role is installed, and the host is promoted to a domain controller. However, it is possible to add AD management tools to any domain-member Windows Server host.

  • Via Server Manager: Add Roles and Features -> Features -> Remote Server Administration Tools -> AD DS and AD LDS Tools -> AD DS Tools -> AD DS snap-Ins and Command-line tools Server Manager: add Active Directory snap-ins
  • Or install the ADDS management tools using PowerShell: Install-WindowsFeature RSAT-ADDS-Tools

Check that this Windows Server feature is installed:

Get-WindowsFeature RSAT-ADDS-Tools

Install-WindowsFeature RSAT-ADDS-Tools

Working with the Active Directory Users and Computers (ADUC) Console

After installing the RSAT tools on a computer, you will find a link to launch the Active Directory Users & Computers MMC console in the following section of the Control Panel:

  • On Windows 11: Windows Tools (Control Panel\System and Security\Windows Tools):
  • On Windows 10: Windows Administrative Tools

To quickly navigate to this section of the Control Panel, run the command: control /name Microsoft.AdministrativeTools

Active Directory Users and Computers snap-in in control panel

To launch the ADUC console, either click the shortcut in the Control Panel or run the following command via Win+R:

dsa.msc

run dsa.msc

Domain admin privileges are not necessary to use ADUC. All domain users can use the Active Directory console to view domain objects.

If your computer is joined to an Active Directory domain, the ADUC will connect to a domain controller based on the current Logon server ($env:LOGONSERVER). The name of the DC that the MMC console is currently connected to is shown at the top.

To connect to another AD domain controller or another domain, click the console root and select the Change Domain or Change Domain Controller from the context menu.

ADUC: change domain or domain controller

The Active Directory console shows a tree-like Organizational Unit (OU) structure of your domain (and a separate section containing AD Saved Queries).

active directory roy users and computers mmc snap-in overview

The ADUC snap-in allows administrators to perform the following actions in Active Directory:

  • Create Organizational Units (OUs) according to the physical or logical structure of the company
  • Create, rename, move, edit or delete users, computers, groups, and contacts
  • Reset user passwords in Active Directory or disable/unlock accountsADUC user action menu
  • Search for objects in AD
  • Delegate permissions to create/edit/delete objects in Active Directory to other users or groups
  • Move the FSMO roles between the domain controllers and raise the domain functional level
  • View or edit the properties of domain objects. For example, open the user properties and edit their attributes.  Some user properties can be found on the relevant tabs. The complete list of user attributes is available on the Attribute Editor tab (object properties cannot be edited when connected to a read-only domain controller, RODC)how to view or change user properties in the ADUC console

Using the View -> Add/Remove columns menu, you can add object attributes you want to see in the ADUC console. For example, you can also add a separate tab containing a photo of the AD user.

To show system containers and object properties in the Active Directory snap-in (they are hidden by default), enable the option View -> Advanced Features.

enable hidden features in ADUC

Additional system tabs will then be displayed for all objects. For example, you can get a canonical object name, view an account creation date, or check the Protect object from accidental deletion option in the Object tab.

object properties tab in ADUC

Using the ADUC Console from a Non-domain Computer

To connect to a domain controller via the ADUC console from a non-domain-joined workstation (workgroup member), use this method:

  1. Open the command prompt and run the mmc console as a different user: runas /netonly /user:woshub\jsmith mmc
  2. In the empty MMC console, select File -> Add/Remove Snap-In
  3. Move the Active Directory Users and Computers snap-in to the right panel and click Adddsa.msc run fron non-domain (workgroup) computer
  4. To connect to a domain, click the console root and select Change domain. Type the domain name. ADUC: connecting domain from workgroup computer
Or use this command: runas /user:woshub\username "c:\windows\system32\mmc.exe %SystemRoot%\system32\dsa.msc /domain:woshub.com"

The ADUC console will then connect to the domain controller and display the container (OU) structure of the specified Active Directory domain.

In addition to the ADUC snap-in, installing AD administration tools also installs the Active Directory Administrative Center (ADAC) console. Although the two consoles have similar functionality, the ADAC (dsac.exe) supports a number of advanced features.

  • Managing the AD Recycle Bin and restoring deleted objects.
  • Configure Fine-Grained Password Policy (FGPP) in AD
  • ADAC is built on PowerShell. This means that the PowerShell commands are being executed in the background. It provides advanced features such as global search, instant password resets, and PowerShell command history.
  • Managing a multi-domain environment from a single console.
  • Bulk Active Directory operations.

0 comment
2
Facebook Twitter Google + Pinterest
Active DirectoryWindows 10Windows 11Windows Server 2022
previous post
How to Delete or Rename Default Mailbox Database in Exchange Server
next post
PowerShell Install-Module Error: Unable to Download from URI

Related Reading

How to Find the Source of Account Lockouts...

March 12, 2024

Configuring Windows Firewall Rules Using Group Policy

March 15, 2024

Copy Files and Folders to User Computers via...

March 15, 2024

How to Disable NTLM Authentication in Windows Domain

March 16, 2024

Checking Active Directory Domain Controller Health and Replication

May 15, 2025

How to Install the PowerShell Active Directory Module...

March 15, 2024

Troubleshooting: Group Policy (GPO) Not Being Applied to...

March 15, 2024

Cached Domain Logon Credentials on Windows

July 29, 2025

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • How to Move (Migrate) Existing Windows Shares to a New File Server

    December 24, 2025
  • Using KDC (Kerberos) Proxy in AD for Remote Access

    December 23, 2025
  • Windows: Create (Install) a Service Manually

    December 16, 2025
  • Windows: Auto Switch to Strongest Wi-Fi Network

    December 10, 2025
  • How to Enable or Disable VBScript in Windows after Deprecation

    December 10, 2025
  • Start Menu Not Working (Unresponsive) on Windows Server RDS

    November 27, 2025
  • AppLocker: Configure Application Restriction Policies in Windows

    November 19, 2025
  • Enable/Disable Random Hardware (MAC) Address for Wi-Fi on Windows

    November 14, 2025
  • Automate Software and Settings Deployment with WinGet Configure (DSC)

    November 13, 2025
  • SMB over QUIC: Mount File Share over Internet without VPN on Windows Server 2025

    November 4, 2025

Follow us

  • Facebook
  • Twitter
  • Telegram
Popular Posts
  • Configure Google Chrome Settings with Group Policy
  • Get-ADUser: Find Active Directory User Info with PowerShell
  • Allow Non-admin Users RDP Access to Windows Server
  • How to Find the Source of Account Lockouts in Active Directory
  • How to Disable or Enable USB Drives in Windows using Group Policy
  • Get-ADComputer: Find Computer Properties in Active Directory with PowerShell
  • Configuring Proxy Settings on Windows Using Group Policy Preferences
Footer Logo

@2014 - 2024 - Windows OS Hub. All about operating systems for sysadmins


Back To Top