Skip to main content
AD Academy
Tools
Intermediate14 minLast updated: Topic 1 of 4

Standard Tools for AD Admins

RSAT, ADUC, PowerShell and additional tools.

Not read

What you will learn here

  • Which tools an AD admin has
  • When to use ADUC vs PowerShell
  • How to install RSAT

To manage , system administrators use both built-in and external tools. It's important to understand that the same tools can be used both for defense and for Penetration Testing.

Popular tools

  • ADUC ( Users and Computers) — graphical management of objects.
  • RSAT (Remote Server Administration Tools) — a toolkit for remotely managing servers.
  • PowerShell + the ActiveDirectory module — task automation.
  • — visual mapping of relationships and Privilege Escalation paths.
  • — extracting Credentials from memory (for legal testing only!).
# Example: Get all users in Domain
Get-ADUser -Filter * -Properties DisplayName | Select-Object Name, DisplayName
powershell
Architecture and Theory — Under the Hood

management is divided into three tool layers: GUI (MMC) for daily operations, PowerShell (RSAT / ActiveDirectory module) for automation, and /ADSI for basic access that does not go through the module.

  • dsa.msc — Users and Computers.
  • dssite.msc — Sites and Services (replication).
  • gpmc.msc — Group Policy Management.
  • ADAC — Administrative Center + Recycle Bin.
  • RSAT — The tool package for the admin workstation (Add-WindowsCapability -Name Rsat.ActiveDirectory*).
Practical Setup (PowerShell / GUI)
# Install RSAT on Windows 11
Get-WindowsCapability -Online | Where-Object Name -like 'Rsat.ActiveDirectory*' | Add-WindowsCapability -Online

# Enable Recycle Bin (irreversible - once only)
Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target corp.com

# Restore a deleted object
Get-ADObject -Filter {Deleted -eq $true -and Name -like '*smith*'} -IncludeDeletedObjects |
  Restore-ADObject
powershell
Real-world Scenarios in the Organization
  • Help Desk uses dsa.msc to reset passwords and unlock accounts.
  • Automation works in PowerShell with the ActiveDirectory module.
  • Deep problems (Schema, replication metadata) are resolved with ldp.exe / repadmin / ntdsutil.
Troubleshooting
# Replication
repadmin /replsummary
repadmin /showrepl DC01

# DC Health
dcdiag /v /c /d

# FSMO Roles
netdom query fsmo
bash
Glossary and Quick Command Line
  • dsa.msc / dssite.msc / gpmc.msc / adsiedit.msc / ldp.exe / ADAC
  • ActiveDirectory / GroupPolicy / DnsServer PowerShell modules
  • ntdsutil — NTDS.dit database maintenance

Check yourself

Which tool is used for visualizing Privilege Escalation paths in AD?

Was this page helpful?