AD: Managing Active Directory Groups (ETS Internal)

Summary

This article provides guidance on installing the Active Directory Users and Computers (ADUC) module on both Windows 10 and Windows 11 - with instructions on pinning its icon to the taskbar for easy access, as well as running the module as a "different user" with an administrative (ADM) account.

Body

Summary

This article provides guidance on installing the Active Directory Users and Computers (ADUC) module on both Windows 10 and Windows 11 - with instructions on pinning its icon to the taskbar for easy access, as well as running the module as a "different user" with an administrative account.

Windows users who are responsible for managing Active Directory (AD) groups will find this article useful for understanding the installation process along with utilizing features for efficient AD group management.

 

Objective

This process will allow approved Help Desk staff the ability to assist in adding and removing users from specific Active Directory groups. A current list of AD groups that we are approved to manage may be found at:

delegated_groups.docx

- The contents of this document have been composed by our ET&S Active Directory Team.
- Please note that Help Desk access to "delegated_groups.docx" is view only, and protected by permissions.
- Please engage with your Help Desk leadership if you do not have the appropriate permissions for viewing.

Important: Please read the following information thoroughly!

Changes via the ADUC must be made using the ADM_ version of your account, primary accounts do not have access to modify any of these groups.  Note: You must be on the campus network or on the VPN to sign in with ADM_ credentials (as of Oct. 2, 2024).

Requested changes to these groups must come from the group's primary contact or approved requester - listed within the "delegated_groups.docx" document above. If the request does not come from one of the specified parties, you must seek approval from the group’s primary contact or approved requester and that approval must be in the TD ticket before making a change to the AD security group. If in doubt, please read the notes field on the security group in ADUC. 

Contents

1. Installing Active Directory Users and Computers (ADUC).

  1. Windows 10
  2. Windows 11

2. Pinning the ADUC module to the taskbar.

3. Running the ADUC module as a different user.

4. Managing Active Directory Groups.

 

Installing Active Directory Users and Computers (ADUC)

Task 1a: Install the ADUC module on a computer running Windows 10.

Instructions

Step 1 - Open the Windows 10 "Start" menu.

Step 2 - Scroll down the left sidebar to locate select "Settings".

Step 3 - Select "Apps".

Step 4 - Ensure that "Apps & Features" is selected from the left sidebar then under "Apps & Features" in the middle of the window, click on the link titled "Optional features".

Step 5 - Click on the + plus button next to "Add a feature".

Step 6 - Search for "RSAT", then place a check mark next to RSAT: Active Directory Domain Services and Lightweight Directory Services Tools, followed by clicking the "Install" button.

Step 7 - The RSAT: Active Directory Domain Services and Lightweight Directory Services Tools module should start to install.

 

Outcome

After the RSAT: Active Directory Domain Services and Lightweight Directory Services Tool has been installed we will be able to access and view groups within our Active Directory environment. Please remember that before we are able to add and remove users from these groups, we will need to elevate our privileges by continuing to follow the steps below.

Please refer to the next steps:

  1. Pinning the ADUC module to the taskbar.
  2. Running the ADUC module as a different user.
  3. Managing Active Directory Groups.

Back to top

 

Task 1b: Install the ADUC module on a computer running Windows 11.

Instructions

Step 1 - Open the Windows 11 "Start" menu.

Step 2 - Select "Settings".

Step 3 - Select "Apps" from within the left sidebar.

Step 4 - On the Apps page, select "Optional features - Extra functionality for your device".

Step 5 - Click on the "View features" button.

Step 6 - Search for "RSAT" then place a check mark next to RSAT: Active Directory Domain Services and Lightweight Directory Services Tools, followed by clicking on the "Next" button.

Step 7 - Confirm the items that will be installed, and when ready, click the "Install" button at the bottom of the window.

Step 8 - The RSAT: Active Directory Domain Services and Lightweight Directory Services Tools module should start to install.

 

Outcome

After the RSAT: Active Directory Domain Services and Lightweight Directory Services Tool has been installed we will be able to access and view groups within our Active Directory environment. Please remember that before we are able to add and remove users from these groups, we will need to elevate our privileges by continuing to follow the steps below.

Please refer to the next steps:

  1. Pinning the ADUC module to the taskbar.
  2. Running the ADUC module as a different user.
  3. Managing Active Directory Groups.

Back to top

 

Pinning the ADUC module to the taskbar.

Task 2: Pin the ADUC module to the task bar for easy access.

Instructions

Step 1 - Open the Windows "Start" menu.

Step 2 - In the search bar type "Active Directory Users and Computers" then click on the link titled "Pin to taskbar".

You should now be able to see the Active Directory Users and Computers icon within your taskbar.

 

Outcome

This action will make it easier to locate the ADUC module without having to search for it.
It will also prepare us to perform the "run as different user" option with our adm account.

  1. Running the ADUC module as a different user.
  2. Managing Active Directory Groups.

Back to top

 

Running the ADUC module as a different user.

Task 3: Run the ADUC module with your adm account.

Administration via the ADUC requires elevated privileged by way of our secondary or adm accounts: "adm_username".
Please follow the steps below to ensure that you have elevated your privileges and are accessing the ADUC module with your adm account.

Note: You must be on the campus network or on the VPN to sign in with ADM_ credentials (as of Oct. 2, 2024).

Instructions

Step 1 - Locate the newly installed (and pinned) ADUC module in the taskbar of the computer.

Step 2 - Hold down the "shift key" on the keyboard then "right click" with the mouse on the ADUC icon in the taskbar.

Step 3 - This action will bring up an additional menu that will allow us to select "Run as different user".

Step 4 - When the "Run as different user" dialog modal opens, be sure to sign in with your adm account credentials.

Step 5 - You should now be signed into the ADUC module with your secondary (adm) account and see the following interface.

 

Outcome

You are now ready to be able to add and remove users to and from Active Directory groups that we are authorized to manage.

Please refer to the next steps:

  1. Managing Active Directory Groups.

Back to top

 

Managing Active Directory Groups.

Task 4: Adding and removing members to and from an Active Directory Group.

Instructions

Step 1 - Left click on the folder search icon in the main menu.

*Alternatively, you could also select "Action" from the top menu then choose "Find".

Step 2 - Change the drop down menu titled: "ad.unh.edu" to "Entire Directory".

Step 3 - Type in the name of the Group that you are looking to manage then click "Find Now".

Step 4 - Double left click on the "group name" that appears in the "Search results" window below.

Step 5 - Select the "Members" tab.

Step 6 - Click on the "Add..." button to add a new member to the Group.

*To remove a user from a group, simply click to highlight the username of the person within the group, then press the "Remove" button.

Step 7 - Enter the person's "username" then press "OK".

Step 8 - Press the "Apply" button then "OK" to complete adding the user to the group. 

Note: we need to test this step. Is "Apply" then "OK" required? Does clicking "OK" on this screen also work or is the user not added? Please let your Team Lead know what you find out so we can improve this document.

 

Outcome

You should now have a practical overview of how to:

  • Install the Active Directory Users and Computers (ADUC) module.
  • How to pin the module to the Windows taskbar.
  • How to run the module with elevated privileges.
  • How to search for AD groups.
  • How to view, add and remove users from AD groups that we are authorized to manage.

Back to top

 

Further Readings

Accounts Internal: How to install Active Directory Users and Computers tool

BitLocker
BitLocker Recovery Keys

 

Need additional help?

Additional assistance or guidance may be provide via a ticket to the Group: ET&S - M365 Tenant, Email, and Authorization Services or through the Service - Directory Services

Details

Details

Article ID: 4663
Created
Mon 4/24/23 3:35 PM
Modified
Mon 9/8/25 5:02 PM
Applicable Institution(s):
Granite State College (GSC)
Keene State College (KSC)
Plymouth State University (PSU)
University of New Hampshire (UNH)
USNH System Office