Windows 10 Pro Active Directory Users and Computers Guide

Install RSAT and fix Active Directory Users and Computers on Windows 10 Pro. Troubleshoot ADUC errors and manage domain users easily.

Ever stared at a blank Active Directory Users and Computers (ADUC) console, wondering why the tool won't pull up any users? Or perhaps you've found yourself RDPing into a Domain Controller just to check a single user account when you should be able to manage it locally. This friction is common, largely because Windows 10 Pro Active Directory Users and Computers is not installed by default. Unlike Windows Server editions, the client OS strips out these management utilities to keep the footprint light. To bridge this gap, you need the Remote Server Administration Tools (RSAT). This guide walks you through installing RSAT on Windows 10 Pro, configuring the MMC snap-in, and fixing the persistent "no users found" error that plagues many IT professionals.

Row of similar lockers with various optic fiber cables in modern data server room

Prerequisites: Why Windows 10 Home vs. Pro Matters for AD Management

Before you open any settings, verify your operating system edition. This is the number one reason users get stuck. In my experience, about half of the "RSAT not showing up" tickets I’ve handled in the last decade stem from users trying to force-install admin tools on Windows 10 Home.

Version Compatibility Check

Microsoft explicitly restricts RSAT availability. It is not available on Windows 10 Home or Standard editions. If you are on Home, your options are limited to upgrading to Windows 10 Pro, Enterprise, or Education, or managing AD from a remote server via RDP. I’ve seen users try to crack the MSU files to force installation on Home; this violates the EULA and breaks Windows Update integrity. Don’t do it.

To check your version, press Windows + R, type winver, and look at the "Edition" line. If it says "Pro," you’re good. If it says "Home," you need to upgrade. Additionally, for remote management to work smoothly, your computer should ideally be joined to the domain. While you can manage AD from a workgroup machine using explicit credentials, being domain-joined reduces authentication friction significantly.

Understanding the MMC Snap-in Architecture

Let’s clear up a technical misconception. "Active Directory Users and Computers" is not a standalone application in the traditional sense. It is an MMC Snap-in. Think of the Microsoft Management Console (MMC) as a shell, and ADUC as a plug-in that fits into it.

This architecture matters because ADUC does not store data locally. When you click "Create New User," your command is not executed on your local machine. It is sent over the network to a Domain Controller. The DC processes the request against the Active Directory database. This is why your local PC’s performance doesn’t matter as much as your network connection to the DC. If the DC is down, or if you can’t resolve its name, ADUC will fail to load data. This client-server model explains why DNS issues and firewall blocks are the primary culprits in connection failures.

Overhead view of similar bright cables with plastic connectors in fiber optical switch

Step-by-Step: Install RSAT on Windows 10 Pro via Settings

Now that we’ve confirmed you’re on Pro, let’s install the tools. For Windows 10 versions 1809 and later, the process has moved away from the old .msu installer method. You no longer download a file from Microsoft’s site. The feature is baked into the OS but disabled by default.

Modern Installation Method (Settings UI)

  1. Open Settings (press Windows + I).
  2. Navigate to Apps > Optional Features.
    • Note: In newer builds (22H2+), this path might be under System > Optional Features.
  3. Click View features (or "Add a feature").
  4. Search for "Remote Server Administration Tools".
  5. You will see several sub-options. For user management, you specifically need:
    • Remote Server Administration Tools: Active Directory and LDAP Tools
    • RSAT: Active Directory Domain Services and Lightweight Directory Services Tools
    • RSAT: Group Policy Management Tools (Highly recommended)
  6. Click Next, then Install.

Wait for the download and installation to complete. This usually takes a few minutes. Once done, the tools are immediately available. You do not need to restart the computer, though it’s good practice.

PowerShell Alternative for IT Pros

If you are deploying this to multiple machines or prefer a scriptable approach, the GUI method is too slow. Here is the PowerShell command to enable the necessary features remotely or locally. Run this in an elevated PowerShell prompt:


Add-WindowsCapability -Online -Name "Rsat.ActiveDirectory.DS-LDPServer.Tools-Client~~~~0.0.1.0"
Add-WindowsCapability -Online -Name "Rsat.DCTools~~~~0.0.1.0"
Add-WindowsCapability -Online -Name "Rsat.GroupPolicyManagement.Tools~~~~0.0.1.0"

For offline deployment or in restricted environments where PowerShell capabilities aren’t synced from Windows Update, you can use DISM:

dism /online /enable-feature /featurename:Rsat.ActiveDirectory.DS-LDPServer.Tools-Client

I find the Add-WindowsCapability method more reliable for modern Windows 10/11 environments because it leverages the same backend as the Settings app but allows for loop execution across a fleet of PCs.

Accessing and Managing: Opening the ADUC Console

You’ve installed RSAT. Now, how do you actually open the tool? This is where users often get confused because "Active Directory Users and Computers" doesn’t always appear as a standalone Start Menu entry like older Windows versions.

Finding the Tool in the UI

Press the Windows key and start typing "Active Directory". If you see Active Directory Users and Computers in the results, click it.

If it’s missing, launch the Microsoft Management Console manually:

  1. Press Windows + R, type mmc, and hit Enter.
  2. In the MMC window, go to File > Add/Remove Snap-in.
  3. Under the "Available" column, look for Active Directory Users and Computers.
  4. Select it, click Add, then OK.
  5. At the prompt asking for a domain, choose Active Directory domain > Active Directory domain (if you want to target a specific domain) or The currently logged on domain.

Click OK. If the tree loads but shows no users, proceed to the troubleshooting section below.

Creating a .Msc Shortcut for Quick Access

To avoid navigating the MMC menus every time, save the console file.

  1. Once ADUC is loaded in MMC, go to File > Save As.
  2. Name it ADUC.msc and save it to your Desktop or a shared network location.
  3. Right-click the file and select Properties > General > Unblock (if prompted by security).

Now, you can pin ADUC.msc to your taskbar. This is particularly useful for remote sessions where you want a dedicated window for user management without cluttering your main screen.

Troubleshooting: Fixing 'No Users' or Connection Errors

This is the most common post-install issue. You installed RSAT, you opened ADUC, and you see a tree structure, but the "Users" container is empty, or you get a "The Active Directory service is not available" error.

Why the ADUC List is Blank

Usually, this means your PC cannot find a Domain Controller. ADUC relies on DNS to discover DCs.

  1. Check Domain Membership: Open System Properties (press Windows + Pause or right-click This PC > Properties). Ensure the "Computer name" tab shows your domain. If it says "Workgroup," ADUC cannot authenticate anonymously to find the DC.

  2. Verify DNS Resolution: Active Directory DNS is critical. Open Command Prompt as Administrator and run:

    nslookup -type=SRV _ldap._tcp.dc._msdcs.<yourdomain.com>
    

    Replace <yourdomain.com> with your actual domain. If this returns no results, your DNS server settings on the client are wrong, or the DC’s DNS records are missing.

  3. Firewall Issues: Ensure that the Windows Firewall on your PC allows traffic on ports 389 (LDAP), 636 (LDAPS), and 3268 (Global Catalog) outbound. In most enterprise environments, this is fine, but in lab or restricted networks, it’s a common blocker.

MMC Snap-in Creation Failures

If you see "MMC could not create the snap-in," it’s often a permissions or policy issue.

  • Permissions: Do you have the rights to view the AD tree? If you are a standard user, you might not have rights to query the entire domain. Try logging in with a Domain Admin account to test. If it works, the issue is your user rights, not the installation.
  • Trusted Sites: In rare cases involving web-based management or cross-domain setups, ensure that your Domain Controller’s IP or FQDN is in your Internet Explorer Trusted Sites list. Yes, IE settings still affect MMC snap-ins that rely on .NET COM objects.
  • Corrupted Profile: Occasionally, the local user profile’s registry cache for MMC can get corrupted. Renaming the HKEY_CURRENT_USER\Software\Microsoft\MMC key and logging off/on can reset this.

Advanced: Remote Access and PowerShell Alternatives

Now that you have the tool, let’s talk about efficiency. GUI tools are great for one-off tasks, but they hit a wall when you need to manage hundreds of accounts.

Managing Without Server Admin Rights

You don’t need to be a Domain Admin to use ADUC. AD supports delegated permissions.

  • Standard User: By default, a standard domain user can view most OU structures but cannot create or modify users.
  • Delegated Admin: An IT manager might only have rights to the "Service Accounts" OU. In ADUC, they can navigate to that specific OU and manage objects there. They will see "Access Denied" errors if they try to modify users in "Default Domains Users."

To find a specific user quickly in the GUI:

  1. Right-click the top-level domain node.
  2. Select Find.
  3. In the "Find what" box, type the user’s name or sAMAccountName.
  4. Check "Search the sub-container below the following base" to ensure you’re searching the right scope.

When to Use PowerShell Instead

For anything involving more than 5 users, stop clicking. Use the Active Directory module for PowerShell. It’s part of the same RSAT installation.

Compare these two tasks:

GUI Task: Reset 50 password expirations.

  • Action: Click through 50 user properties windows. Takes ~15 minutes.

PowerShell Task:

Import-Module ActiveDirectory
Get-ADUser -Filter 'PasswordExpired -eq $true' -SearchBase "OU=Employees,DC=contoso,DC=com" | Set-ADAccountPassword -NewPassword (ConvertTo-SecureString "NewPass123!" -AsPlainText -Force)
  • Action: One command. Takes seconds.

PowerShell also allows you to script audit reports. For example, exporting all users in a specific department to a CSV for HR compliance is a 2-line script in PowerShell, but a tedious copy-paste job in ADUC.

FAQ

How do I open Active Directory Users and Computers on Windows 10?

First, ensure RSAT is installed via Settings > Apps > Optional Features. Then, open the Start menu and type "Active Directory Users and Computers." If it doesn’t appear, open mmc, go to File > Add/Remove Snap-in, and select "Active Directory Users and Computers" from the list.

Can I manage Active Directory from Windows 10 Home edition?

No. Windows 10 Home does not support the installation of Remote Server Administration Tools (RSAT). To manage AD from a client PC, you must use Windows 10 Pro, Enterprise, or Education. Alternatively, you can RDP into a server that already has the tools installed.

Why can't I connect to the domain controller from my Windows 10 PC?

The most common causes are DNS resolution failures or the PC not being joined to the domain. Run nslookup to check if you can resolve the DC’s SRV record. Also, verify that your firewall isn’t blocking LDAP (port 389) or Global Catalog (port 3268) traffic. Ensure your computer account is active in AD.

Do I need to be an administrator to use Active Directory Users and Computers?

You need local administrator rights to open the MMC snap-in. However, to modify users (create, delete, reset passwords), your domain account needs specific permissions. A standard domain user can usually open the tool and view the tree structure, but will receive "Access Denied" errors when trying to edit objects they don’t have delegated rights for.

Conclusion

Managing Windows 10 Pro Active Directory Users and Computers comes down to three things: having the right OS edition, installing the correct RSAT features, and ensuring your network can talk to the Domain Controller. If you’re on Home, upgrade. If you’re on Pro, install the AD tools via Settings. If the list is blank, check your DNS.

For complex tasks, don’t fight the GUI. Switch to PowerShell. It’s faster, reproducible, and scales better. If you’re still stuck with "snap-in not working" errors after checking DNS and permissions, I’d recommend checking the Event Viewer on your PC for specific AD authentication errors. And if you’ve found a workaround for a weird permission issue, share it in the IT forums—helping others debug AD pain points is how we all get better.

Quick Checklist:

  1. Verify OS is Pro/Enterprise.
  2. Install RSAT via Optional Features.
  3. Verify PC is joined to the domain.
  4. Test DNS resolution of DC SRV records.
  5. Consider PowerShell for bulk actions.
← Back to Home