A new admin joins the team and, on day one, does what everyone does: opens an RDP session to a domain controller to reset a password in Active Directory Users and Computers. It works, and it’s also the habit you want to break first. Every interactive logon to a DC leaves credentials in that server’s memory and widens the set of machines that can hurt you. Remote Server Administration Tools (RSAT) are how you manage the domain from a workstation instead — the same consoles and PowerShell modules, running locally, talking to the DC over LDAP, RPC and WinRM.
What it does
RSAT is a set of Microsoft management tools for server roles, installed on a client or member server. The pieces most domain admins use:
- AD DS and AD LDS tools — Active Directory Users and Computers, Administrative Center, Sites and Services, Domains and Trusts, ADSI Edit, and the
ActiveDirectoryPowerShell module, plus command-line tools such asrepadmin,dcdiag,dsquery,netdomandntdsutil. - Group Policy Management — GPMC and the
GroupPolicymodule (Get-GPOReport,Backup-GPO). - DNS and DHCP — the MMC consoles and their PowerShell modules (
DnsServer,DhcpServer). - Certificate Services, BitLocker recovery viewer, Failover Clustering, File Services, Remote Desktop Services, Server Manager, WSUS and others.
The practical value is PowerShell. With the AD module, stale-account cleanup is a few lines:
Search-ADAccount -AccountInactive -ComputersOnly -TimeSpan 90.00:00:00 |
Where-Object Enabled |
Select-Object Name, LastLogonDate, DistinguishedName
The same module handles bulk user changes, group membership reports and account unlocks without a third-party tool.
Installing it
On Windows 10 1809 and later, and on Windows 11, RSAT is part of the operating system as Features on Demand. Use Settings › System › Optional features › Add a feature and search for “RSAT”, or use PowerShell from an elevated prompt:
Get-WindowsCapability -Online -Name RSAT* | Select-Object Name, State
Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0
Add-WindowsCapability -Online -Name Rsat.GroupPolicy.Management.Tools~~~~0.0.1.0
On Windows Server, add the tools through Add Roles and Features, or Install-WindowsFeature RSAT-AD-Tools, GPMC.
A frequent snag: machines pointed at WSUS can fail to add Features on Demand because the payload comes from Windows Update. Either set the Group Policy “Specify settings for optional component installation and component repair” to allow contacting Windows Update directly, or supply the Features on Demand media via -Source.
Rights and audit trail
RSAT grants nothing by itself; it is only a client. What you can do depends on your AD delegation. That is the point — run the tools as a separate admin account (runas /user:CORP\adm-jdoe "mmc dsa.msc") and delegate specific rights, such as password reset on a given OU, instead of adding people to Domain Admins. Traffic goes to DCs on LDAP 389/636, Global Catalog 3268/3269, Kerberos 88, RPC 135 plus dynamic ports, and SMB 445. The AD module talks to Active Directory Web Services on TCP 9389.
For the audit trail, directory changes made through RSAT are logged on the DC like any others: 4720/4726 for user create/delete, 4738 for user changes, 5136 for attribute changes when directory service change auditing is enabled. There’s no separate RSAT log, so turning on Advanced Audit Policy “Audit Directory Service Changes” is what gives you “who changed what”.
Where it’s strong
- It’s the reference toolset: every Microsoft doc and most community answers assume it.
- Nothing extra to buy, patched through Windows Update with the OS.
- PowerShell modules make almost any AD chore scriptable and repeatable.
- Removes the need to log on interactively to DCs, which is a real security gain.
Where it falls short and who should skip it
The MMC consoles are dated: no approval workflows, no scheduled reports, no undo beyond the AD Recycle Bin. It installs only on Professional and Enterprise editions of Windows client — not Home — and Microsoft notes that on Arm64 devices only a subset of tools is available. Reporting is DIY; anything beyond a quick Get-ADUser export means writing and maintaining scripts. Delegating safely through the Delegation of Control wizard is fiddly, and teams without PowerShell skills can find the consoles slow for bulk work. Where you need helpdesk self-service or compliance-ready change history, a commercial layer on top makes sense.
Who it suits
Every Windows domain admin should have it on a dedicated admin workstation. It fits best in shops comfortable with PowerShell, and in tiered-admin setups where you want management traffic from a controlled workstation rather than interactive DC logons.
Licensing and cost
RSAT is included with Windows client (Professional/Enterprise) and Windows Server at no extra cost; there’s nothing to license separately.
How it compares
ManageEngine ADManager Plus wraps AD management in a web console with templates, workflows and hundreds of canned reports; Netwrix Auditor records who changed what. The trade-off between those two is in ADManager Plus vs Netwrix Auditor. Windows Admin Center covers server roles in a browser but isn’t a replacement for ADUC or GPMC. For a worked RSAT task, see find and clean up stale computer accounts in Active Directory, and browse Active Directory Management & Auditing.
Getting it safely
Add RSAT through Windows’ own Optional Features or Add-WindowsCapability, which pull signed packages from Windows Update or your internal source. There’s nothing to fetch from third-party sites — anything offering “RSAT for Home” is a warning sign. See where to get it for general guidance.
FAQ
Can I install RSAT on Windows 11 Home?
No. Microsoft states RSAT installs only on Professional or Enterprise editions of Windows client. Education is built on Enterprise and is commonly used with RSAT, but Home is out.
Why does Add-WindowsCapability fail with 0x800f0954?
Typically the machine is pointed at WSUS and can’t fetch the feature payload. Allow direct Windows Update contact for optional components via Group Policy, or point -Source at Features on Demand media.
Do I need Domain Admin to use ADUC?
No. Any authenticated user can read most of the directory; changes need delegated rights. Use delegation per OU rather than broad group membership.
Is the ActiveDirectory module part of RSAT?
Yes. It comes with the AD DS and AD LDS tools feature and talks to Active Directory Web Services on the DCs.
