How to Install ADUC on Windows 11: A Step-by-Step Guide

Active Directory Users and Computers (ADUC) is part of Microsoft’s Remote Server Administration Tools for managing traditional Active Directory Domain Services. On supported Windows 11 editions, install the AD DS and AD LDS management tools through Optional Features rather than downloading an unofficial ADUC package.

Install ADUC on Windows 11

  1. Sign in with an account permitted to install Windows optional features.
  2. Open Settings > System > Optional features.
  3. Use the option to view or add available optional features.
  4. Search for RSAT: Active Directory Domain Services and Lightweight Directory Services Tools.
  5. Select the feature and install it.
  6. After installation, search Start for Active Directory Users and Computers.

Installing the console does not grant administrative rights

ADUC is only a management interface. Your account still needs appropriate domain permissions, network/VPN connectivity, DNS resolution, and access to a domain controller before you can administer directory objects.

Windows edition can affect RSAT availability

RSAT is intended for supported professional and enterprise administration scenarios. If the feature is unavailable on a Home edition, do not install repackaged management binaries from third-party download sites. Use an organization-approved administrative workstation or supported Windows edition.

Use delegated permissions rather than Domain Admin for routine work

Organizations should grant only the rights needed for tasks such as password resets or group membership changes. Avoid browsing the web or reading ordinary email from a highly privileged administrative session.

ADUC is not the same as Microsoft Entra administration

ADUC manages Active Directory Domain Services. Cloud identities in Microsoft Entra ID use different administration tools, although hybrid environments can synchronize identities between the systems.

If RSAT installation fails, install current Windows updates and check organization policy before trying component-store repairs or other invasive troubleshooting.