How to using RSAT on a non-domain-joined Windows Pro or Enterprise machine

How to using RSAT on a non-domain-joined Windows Pro or Enterprise machine
Photo by Tadas Sar / Unsplash

You can use RSAT on a non-domain-joined Windows Pro or Enterprise machine by first installing it as an Optional Feature via Settings > Apps > Optional features. To administer a domain, ensure your workstation has network connectivity to the domain, set the preferred DNS to a domain controller's IP, and use the Run as command or the runas command with the /netonly parameter to connect to the domain using a domain user's credentials.

  1. Install RSAT
  • Go to Settings > Apps > Optional features.
  • Click Add a feature (or View features in older versions).
  • Search for "Remote Server Administration Tools" and select the specific tools you need to install.
  • Click Install.
  1. Configure network and DNS
  • Ensure connectivity: Make sure your non-domain-joined computer can reach the domain controllers over the network.
  • Set the preferred DNS: Change your network adapter's settings to use the IP address of a domain controller as the preferred DNS server.
  1. Use runas to launch tools with domain credentials
  • Open a Command Prompt or PowerShell window as an administrator.
  • Navigate to the RSAT tool's executable, or use the runas command to launch it with a domain user's credentials.
  • Example: To run "Active Directory Users and Computers" as a domain user, type the following command and press Enter:
runas /netonly /user:YourDomain\YourUsername "mmc.exe %windir%\system32\dsa.msc"
  • You will be prompted to enter the domain user's password.
  • For newer Windows versions: The tools are installed as an "Optional Feature" and can often be launched directly from the Start Menu after being installed.

Note: You may need to explicitly set the domain suffix in your machine's DNS settings for the connection to work correctly.