Browse learn

Active Directory Users and Computers

Learn what Active Directory Users and Computers manages, how its console exposes directory objects, and where newer administration tools fit.

On this page

Link to What is Active Directory Users and Computers (ADUC)?What is Active Directory Users and Computers (ADUC)?

Active Directory Users and Computers (ADUC) is a Microsoft Management Console (MMC) snap-in that enables administrators and identity engineers to manage core objects within Active Directory Domain Services (AD DS). ADUC provides an interface for creating, modifying, and deleting directory objects such as user accounts, security groups, computers, and organizational units (OUs). While ADUC has been a foundational admin tool since the early days of Active Directory, it remains widely used for daily directory management, especially for object lifecycle and basic permissions tasks.

ADUC’s role is distinct from other MMC snap-ins, such as Active Directory Sites and Services (for site replication and topology) or the Group Policy Management Console (GPMC, for GPO administration). ADUC is specifically focused on the core directory tree: organizational units and the objects they contain.

In practice, ADUC manages accounts and resources — not Group Policies themselves, not directory schema, and not advanced features introduced in newer versions of AD. Its directness and widespread familiarity keep it relevant, but its limitations are increasingly noticeable as directory features have evolved.

Example: To create a new user account, an admin launches ADUC, navigates to the desired OU, right-clicks, selects "New > User," and walks through the user creation wizard. Similarly, unlocking a locked account or resetting a password is a matter of right-clicking the target user account, choosing the appropriate action, and applying the change.

Link to Installing and Enabling ADUC on WindowsInstalling and Enabling ADUC on Windows

ADUC is not available by default on all Windows systems. On Windows Server (with the AD DS role installed), the tool is typically present, but on client editions of Windows 10 or 11, it requires explicit installation as part of the Remote Server Administration Tools (RSAT).

Key installation points:

  • Windows Server: ADUC is available on domain controllers and admin servers once AD DS or RSAT roles are enabled.
  • Windows 10/11: ADUC is not included by default; it must be installed via RSAT by enabling the 'Active Directory Domain Services and Lightweight Directory Services Tools' feature. This feature is only available on Pro, Enterprise, and Education editions—never on Windows Home.
  • Domains and Permissions: The computer must be joined to the domain you wish to manage, and you must be logged in with an account holding relevant administrative permissions.

Troubleshooting a missing ADUC: If ADUC does not appear after installing RSAT, confirm:

  • The system is running a supported Windows edition.
  • RSAT components are enabled in 'Optional Features'.
  • The computer is joined to the intended domain.

If installation or visibility issues persist, ensure OS updates are current, and verify administrative credentials.

Link to Core Functions and FeaturesCore Functions and Features

ADUC is designed for practical, day-to-day directory management. Its core features include:

  • Object Lifecycle Management: Create, delete, disable, enable, move, and rename users, groups, and computers.
  • Group Membership: Add or remove users from security and distribution groups.
  • Attribute Editing: View and modify object properties (e.g., name, account options, profile path, email, group memberships).
  • OU Management: Create organizational units for structuring users and computers; move objects between OUs as needed.
  • Basic Troubleshooting: Unlock user accounts, reset passwords, check account status, or disable/enable accounts during onboarding/offboarding.
  • Filtering and Searching: Find objects based on common attributes and directory location.

Example workflows:

  • Onboarding a user: Create user in the appropriate OU, set password, assign to groups, configure attributes.
  • Password reset: Locate user, right-click, select "Reset Password," and apply new credentials.
  • Moving objects: Drag and drop users or computers to new OUs to reflect organizational changes.

It's important to note that Group Policy Objects (GPOs) cannot be managed from ADUC; GPO management requires the Group Policy Management Console (GPMC).

Link to Delegation and Permissions: Making Administration Safe and ScalableDelegation and Permissions: Making Administration Safe and Scalable

One of ADUC's most critical roles is enabling secure, scalable delegation of administrative privileges. Rather than grant broad domain or enterprise admin rights, organizations use OUs and the Delegation of Control Wizard to assign narrowly scoped permissions.

Delegation in ADUC operates as follows:

  • OU Scoping: Admins structure the directory with OUs to mirror business units, departments, or admin boundaries.
  • Delegation of Control Wizard: This tool enables you to delegate tasks (like password resets, creating users, managing groups) to specific users or groups within a given OU.
  • Permission Boundaries: Delegated permissions apply only to the specific OU (and optionally, its child objects), ensuring separation of duties and minimizing lateral risk.

Practical example: To enable Help Desk staff to reset passwords only within a certain department, use the wizard on the relevant department’s OU, delegate 'Reset user passwords and force password change at next logon', and select the Help Desk group. The wizard configures the necessary access controls without exposing wider directory privileges.

Design cautions:

  • Always verify the OU structure aligns with delegated roles; poorly designed OUs can result in excessive or overlapping rights.
  • Least-privilege delegation reduces risk and maintains compliance.
  • Regularly review delegated permissions to prevent privilege creep.

Link to ADUC and Modern Directory Tools: ADAC and BeyondADUC and Modern Directory Tools: ADAC and Beyond

While ADUC remains a staple for directory object management, modern AD environments feature capabilities that ADUC cannot access. The Active Directory Administrative Center (ADAC) is Microsoft’s successor tool, designed to overcome ADUC’s limitations.

Key differences:

  • Feature Set: ADAC supports everything ADUC does and introduces newer capabilities, such as:
    • Active Directory Recycle Bin management (restoration of deleted objects and their attributes)
    • Fine-grained password policy management
    • PowerShell integration and command history view
  • Interface: ADAC uses a more modern UI model and exposes advanced features directly.

Where ADUC falls short:

  • ADUC cannot manage, enable, or restore from the Active Directory Recycle Bin. Only ADAC or PowerShell provide these functions.
  • Fine-grained password and account policies are not visible or editable in ADUC.
  • Some advanced attribute editing and recovery scenarios require tools beyond ADUC.

In most cases, ADUC is ideal for routine user/group/computer admin, while ADAC (or PowerShell) is warranted for advanced or new directory features.

Link to Common Misconceptions, Limitations, and Edge CasesCommon Misconceptions, Limitations, and Edge Cases

Misunderstandings about ADUC are common, particularly where boundaries between AD tools are subtle:

  • ADUC is not always present: It is available by default on many Windows Server systems with directory roles installed, but must be explicitly added (via RSAT) on Windows 10/11, and is never supported on Windows Home editions.
  • Group Policy Objects (GPOs) are not managed in ADUC: GPO creation, linking, and editing require the Group Policy Management Console (GPMC), not ADUC.
  • No Active Directory Recycle Bin in ADUC: Only ADAC or PowerShell can enable or restore deleted objects from the Recycle Bin.
  • Limits on advanced features: Fine-grained password policy management, attribute restoration, and some bulk operations are not supported by ADUC.
  • Not all object attributes are exposed: Some schema extensions and non-standard attributes require advanced tools like ADSI Edit or direct PowerShell scripting for full management.

ADUC is reliable for core tasks, but recognize when you need to switch to ADAC or complementary tools.

Link to Practical Daily Operations and ExamplesPractical Daily Operations and Examples

Daily use of ADUC by admins and service desk staff typically covers these scenarios:

  • Onboarding: Create a new user in the correct OU, set account properties, assign initial passwords, and add to required groups.
  • Offboarding: Disable, reset, or delete accounts; move accounts to archive OUs.
  • Group Management: Add or remove users from role-based groups for access control.
  • Password and Lockout Assistance: Reset user passwords and unlock accounts after too many failed login attempts.
  • Delegation: Grant non-admin staff (like Help Desk) permissions to manage users in their department only.
  • Troubleshooting: Locate objects, review account status/details, and perform basic fixes.

A typical admin workflow might be: search for a new hire’s account, check its group memberships, move the user to the correct OU, and ensure login attributes are correct—all within a single ADUC session.

Link to Summary: When and How to Use ADUC EffectivelySummary: When and How to Use ADUC Effectively

Active Directory Users and Computers remains a vital tool for core object management in modern AD environments. Its straightforward interface and focus on user, group, and computer management—plus safe, OU-scoped delegation—make it a first stop for sysadmins, IT professionals, and developers handling day-to-day directory tasks.

However, as Active Directory has gained new capabilities, ADUC’s limitations around the Recycle Bin, advanced policies, and some attribute management mean it is no longer sufficient for every scenario. Use ADUC for classic, role-based object management, onboarding/offboarding workflows, and straightforward delegation. Switch to Active Directory Administrative Center (ADAC) or PowerShell when you need advanced recovery, fine-grained policy, or attribute-level control.

Practitioners should be comfortable moving between ADUC and modern tools, understanding each one’s boundaries and strengths. For deeper learning, examine official AD documentation on delegation, ADAC, and the Recycle Bin, and explore PowerShell modules for programmatic directory control.

Link to SourcesSources