Home › Active Directory basics: how AD DS is built › Step 6

AD DS administration tools: ADAC, MMC snap-ins and PowerShell

Step 6 of 6 in Active Directory basics: how AD DS is built · video 3:09

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Most AD DS administration is done remotely rather than by signing in to a domain controller, and this lesson surveys the tools used for it. The main one is Active Directory Administrative Center (ADAC), a graphical console built on Windows PowerShell. The video shows creating users, groups, computers and OUs from the domain's right-click menu or the Tasks pane, and lists ADAC's other jobs: managing several domains in one window, building search queries, fine-grained password policies, restoring objects from the Active Directory Recycle Bin and Dynamic Access Control objects. The older MMC snap-ins follow: Active Directory Users and Computers for everyday objects, Sites and Services for replication and topology, Domains and Trusts for trust relationships, and the Schema snap-in, which is not fully installed by default. Finally it introduces the Active Directory module for Windows PowerShell, whose cmdlets sit underneath the graphical tools.

Good to know: today Active Directory Administrative Center and the other consoles come with the Remote Server Administration Tools (RSAT): a Feature on Demand on Windows 10 and 11, or a server feature on Windows Server. Active Directory Users and Computers is still included and widely used.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which ADAC task would you use to bring back a user account that was deleted by mistake?

Recovering objects from the Active Directory Recycle Bin, which ADAC supports directly (provided the Recycle Bin feature has been enabled in the forest).

2. Which console would you open to review replication and the network topology between sites?

Active Directory Sites and Services, the MMC snap-in that manages replication, network topology and related services.

3. What happens when you look for the Active Directory Schema snap-in on a freshly prepared management server?

It is not ready to use, because by default the snap-in is not fully installed; the schema is viewed or changed so rarely that it is left out. It is normally made available by registering schmmgmt.dll.

4. Why is the Active Directory module for Windows PowerShell described as one of the most important management components?

The graphical tools, ADAC included, are built on it and run its cmdlets to do their work, so anything they do can also be done or scripted directly in PowerShell.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Introduction and Administration Tools

4.4★ · 10,857 students on Udemy

See the course on Udemy
← Organisational units (OUs) and the default AD DS containersPath complete - back to Active Directory basics: how AD DS is built →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.