Flamingo Raises $4.5M Seed Round

Skip to content

A new admin laptop arrives, you press Win+R, type dsa.msc, and Windows says it can't find it. There's nothing wrong with the laptop: Windows 11 ships without the Active Directory tools, and you add them as an optional feature. Here's how to install Active Directory Users and Computers on Windows 11 from Settings, PowerShell or DISM, what to do when the install fails, and how to roll it out to every admin workstation at once.

Before You Start: What ADUC Needs

Active Directory Users and Computers (ADUC) is part of Remote Server Administration Tools (RSAT). Since Windows 10 version 1809 there's no separate RSAT download. The tools ship as Features on Demand, small packages Windows pulls from Windows Update when you ask for them.

Four things decide whether the install works:

  • Edition. Microsoft lists RSAT for Windows 11 Pro and Enterprise only. On Home, the RSAT entries never appear in Optional features.
  • Admin rights. You need local administrator rights on the PC to add the feature. If the account you're signed in with isn't an admin, our guide on how to change administrator on Windows 11 covers promoting it.
  • A payload source. Windows downloads the package from Windows Update by default. PCs that get updates from WSUS often can't reach it, which is where the install errors come from.
  • Processor. On Windows 11 version 25H2 Arm64 devices, Microsoft says RSAT Features on Demand aren't supported. The AD tools are added through Turn Windows features on or off instead.

ADUC doesn't come alone. The capability is called RSAT: Active Directory Domain Services and Lightweight Directory Services Tools, and it brings Active Directory Administrative Center, Sites and Services, Domains and Trusts, ADSI Edit and the ActiveDirectory PowerShell module with it. It depends on the Server Manager tools, which Windows adds automatically.

Install ADUC From Settings

This is the quickest route for a single PC:

  1. Open Start, go to Settings, then System, then Optional features.
  2. Next to Add an optional feature, select View features.
  3. Type "Active Directory" in the search box.
  4. Tick RSAT: Active Directory Domain Services and Lightweight Directory Services Tools, select Next, then Install.
  5. Wait for the entry to move to the installed list. No restart is needed.

Windows 11 has renamed this page between releases, so if the menu path doesn't match, type "Optional features" into Start search. This walkthrough shows the same flow:

One warning before you start watching the bar. On a PC pointed at WSUS, the install can sit at 0% for a long time and then fail. If nothing has moved in ten minutes, skip to the fixes below.

Install ADUC With PowerShell or DISM

The command line is faster once you know the capability name, and it's the only way to script the install. Open PowerShell as administrator and check the current state first:

powershell
Get-WindowsCapability -Online -Name Rsat.ActiveDirectory*

State : NotPresent means it isn't installed. Add it with:

powershell
Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0

The DISM equivalent does the same job and is handy in a Command Prompt or a task sequence:

cmd
DISM /Online /Add-Capability /CapabilityName:Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0

Run the Get-WindowsCapability line again and look for State : Installed. The four tildes in the name are part of it, so copy the name exactly. If you want every RSAT tool at once, pipe the list into the install: Get-WindowsCapability -Online -Name RSAT* | Add-WindowsCapability -Online. That adds DNS, DHCP and Group Policy tools too, which is more than an AD-only admin needs.

Once the module is on the PC, Get-ADUser and the rest of the ActiveDirectory cmdlets work from the same console. Our list of PowerShell commands sorts the ones worth knowing by the ticket you're working.

Open ADUC With dsa.msc

Press Win+R and run dsa.msc. You can also find Active Directory Users and Computers under Windows Tools in the Start menu.

Turn on View, then Advanced Features, straight away. It shows the Attribute Editor tab on user and computer objects, plus system containers like LostAndFound. Account fixes like editing a userPrincipalName or proxyAddresses start on that tab.

If you sign in to Windows with a standard account and keep a separate admin account for AD, launch the console as that account instead of signing in with it:

cmd
runas /netonly /user:CONTOSO\adm-jsmith "mmc dsa.msc"

The /netonly switch uses the admin credentials only for network calls to the domain controller. It also works from a PC that isn't joined to the domain, as long as DNS points at your domain controllers.

If ADUC opens but says the domain can't be contacted, check DNS first. If the PC is joined and domain sign-ins also fail, the computer account may have lost its secure channel. Our guide to a failed trust relationship walks through repairing it without rejoining.

When the Install Fails

The usual error on managed networks is 0x800f0954. The PC is set to get updates from WSUS, WSUS doesn't serve the Features on Demand payload, and by default Windows won't go to Windows Update instead.

The fix is one Group Policy setting. Go to Computer Configuration, Administrative Templates, System, and open Specify settings for optional component installation and component repair. Enable it and tick Download repair content and optional features directly from Windows Update instead of Windows Server Update Services (WSUS). Run gpupdate /force and install again.

That policy only helps if the PC can reach Windows Update. In this 2026 r/sysadmin thread, the replies point at the WSUS source and at WU_E_PT_ENDPOINT_UNREACHABLE, a PC with no route to Windows Update:

For networks with no internet access, download the Languages and Optional Features ISO for your exact Windows build from the Volume Licensing Service Center or Visual Studio subscriptions. Mount it and point the install at the folder:

powershell
Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0 -Source "D:\LanguagesAndOptionalFeatures" -LimitAccess

The ISO has to match the installed build. An ISO from an older release fails the same way a missing source does.

Other failures have their own tells. RSAT missing from the list means a Home edition or an Arm64 device on 25H2. An install that fails with the source present can mean a damaged component store; our guide to DISM RestoreHealth covers the repair. For anything else, the detail lands in C:\Windows\Logs\CBS\CBS.log and C:\Windows\Logs\DISM\dism.log.

Deploying ADUC to a Group of Admin Workstations

Install ADUC on the machines admins use for directory work, not on every endpoint. It's one less tool to keep current on user PCs, and it keeps a clear line between user devices and admin devices.

The script is short, and it only acts when the tool is missing, so it's safe to run on a schedule:

powershell
$cap = 'Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0'
if ((Get-WindowsCapability -Online -Name $cap).State -ne 'Installed') {
    Add-WindowsCapability -Online -Name $cap
}
(Get-WindowsCapability -Online -Name $cap).State

Push it as an Intune platform script or Win32 app running as System, a Group Policy startup script scoped to an admin-workstation OU, or a Configuration Manager package. Pair it with the optional component policy from the section above, or every WSUS-managed target will fail with the same error. Configuration Manager admins hit exactly this on 25H2, and the replies in this thread land on the policy or an ISO source:

Feature updates are a good moment to re-run the check. Run it after each Windows 11 upgrade and reinstall wherever it reports anything other than Installed. OpenFrame can run that check as a script across a client's devices and collect the output, so the list of workstations missing ADUC is one view instead of a round of remote sessions.

The Short Version

On Windows 11 Pro or Enterprise, add RSAT: Active Directory Domain Services and Lightweight Directory Services Tools from Optional features, or run Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0. Open it with dsa.msc and switch on Advanced Features. If it fails with 0x800f0954, enable the optional component policy so the PC fetches the package from Windows Update, or point -Source at a matching ISO. For a team of admins, script it once and verify the state after every feature update.

"Fae" Grace Meadows

"Fae" Grace Meadows

Lead AI Fairy

Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Install ADUC on Windows 11

Open Settings, then System, then Optional features, select View features, and install RSAT: Active Directory Domain Services and Lightweight Directory Services Tools. From PowerShell as administrator, run Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0. No restart is needed.
No. Microsoft supports RSAT on Windows 11 Pro and Enterprise only, so the Active Directory tools never appear in Optional features on Home. Upgrade the edition first, or manage AD from a Pro or Enterprise admin workstation.
Press Win+R and run dsa.msc. To run it as a separate admin account, use runas /netonly /user:DOMAIN\account "mmc dsa.msc". Turn on View, then Advanced Features, to see the Attribute Editor tab.
The PC gets updates from WSUS, which does not serve the Features on Demand payload. Enable the Group Policy setting Specify settings for optional component installation and component repair and tick the option to download directly from Windows Update instead of WSUS, then run gpupdate /force. Offline, install from a matching Languages and Optional Features ISO with -Source and -LimitAccess.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.