Active Directory does not install on Windows 11 Home or Pro — you need Windows Server
Active Directory is a directory service that manages user accounts, computers, and permissions across a network. It runs on Windows Server operating systems, not on Windows 11 desktop versions. If you have Windows 11 Home or Pro on your machine, you cannot install Active Directory there. You need to install Windows Server 2022 or Windows Server 2019 instead, either on a separate physical machine or as a virtual machine on your Windows 11 computer.
This is a hard requirement, not a workaround. Microsoft does not offer Active Directory as a feature for Windows 11 desktop editions. If you are setting up a small network and want to manage users and computers centrally, you will need to provision a server machine first.
Key Takeaways
- Active Directory requires Windows Server 2022 or Windows Server 2019, not Windows 11 Home or Pro.
- You can run Windows Server on a virtual machine inside Windows 11 using Hyper-V or VirtualBox if you do not have a spare physical computer.
- The installation process involves adding the Active Directory Domain Services role through Server Manager, then promoting the server to a domain controller.
- After installation, you configure a domain name and set up DNS, which takes about 30 minutes total.
- Client computers on your network will then join the domain and use Active Directory for login and permission management.
Set up a Windows Server machine first
Before you install Active Directory, you need a machine running Windows Server. You have two options: use a physical computer or create a virtual machine on your Windows 11 computer.
For a physical machine, download Windows Server 2022 or 2019 from Microsoft's website, burn it to a USB drive using a tool like Rufus, and install it on a dedicated computer. The machine does not need to be powerful — a basic system with 2 GB of RAM and 20 GB of disk space will run Active Directory, though 4 GB of RAM is more comfortable if you plan to add many users or computers.
For a virtual machine, use Hyper-V (built into Windows 11 Pro and Enterprise) or download VirtualBox for free. Create a new virtual machine with at least 2 GB of RAM and 30 GB of disk space, attach the Windows Server installation media, and complete the Windows Server setup. Once Windows Server is running, you are ready to install Active Directory on it.
Add the Active Directory Domain Services role
Open Server Manager on your Windows Server machine. This is the main administration tool and should open automatically when you log in. If it does not, click the Windows Start button and type "Server Manager".
In Server Manager, click "Add Roles and Features" on the dashboard. A wizard will open. Click "Next" until you reach the "Server Roles" page. Check the box next to "Active Directory Domain Services". A popup will ask whether you want to add required features — click "Add Features" to accept.
Continue clicking "Next" through the remaining pages. On the final page, click "Install". The role will download and install, which takes a few minutes. You will see a notification when it is complete. Do not close Server Manager yet — you need to promote this server to a domain controller next.
Promote the server to a domain controller
After the Active Directory Domain Services role finishes installing, you will see a notification flag in Server Manager with a yellow warning icon. Click that flag and select "Promote this server to a domain controller". This opens the Active Directory Domain Services Configuration Wizard.
On the first page, select "Add a new forest" if this is your first domain controller. Type a domain name — for example, "company.local" or "office.internal". Do not use a real internet domain name like "company.com" unless you own it and have set up DNS properly. Click "Next".
On the next page, set a Directory Services Restore Mode (DSRM) password. This is a recovery password you will need if something goes wrong with Active Directory. Write it down and store it somewhere safe. Click "Next".
The wizard will check prerequisites and show you a summary. Click "Install". The server will restart automatically. This restart takes longer than a normal boot because Active Directory is initializing. Wait for the server to come back online — this can take 5 to 10 minutes.
Verify Active Directory is running
After the restart, log back into your Windows Server machine. Open Server Manager again. In the left sidebar, you should now see "Active Directory Users and Computers" listed. Click it to open the Active Directory management console.
You should see your domain name listed in the tree on the left. Expand it by clicking the arrow next to it. You will see folders for "Computers", "Users", and other containers. If you see these, Active Directory is installed and running correctly.
You can also verify by opening a command prompt and typing "dcdiag". This runs a diagnostic tool that checks whether the domain controller is healthy. Look for "passed test" messages. If you see errors, the most common cause is DNS misconfiguration — check that the server's DNS settings point to itself (127.0.0.1 or the server's own IP address).
Configure DNS for your domain
Active Directory depends on DNS to function. When you promoted the server to a domain controller, DNS was installed automatically. You need to verify it is configured correctly.
Open Server Manager and click "DNS" in the left sidebar. Expand your server name, then expand "Forward Lookup Zones". You should see your domain name listed (for example, "company.local"). Click it to expand it. You should see an "A" record pointing to your domain controller's IP address.
If the zone does not exist, right-click "Forward Lookup Zones", select "New Zone", and follow the wizard to create a primary zone with your domain name. If the A record is missing, right-click inside the zone and select "New Host (A or AAAA)" to create one manually, pointing to your server's IP address.
On client computers that will join the domain, make sure their DNS settings point to your domain controller's IP address. This allows them to find the domain controller and join the domain.
Join client computers to the domain
Now that Active Directory is running, you can add Windows computers to your domain. On a Windows 11 or Windows 10 client computer, right-click the Start button and select "System". Click "Advanced system settings" (or search for "Advanced system settings" in the search box).
Click the "Computer Name" tab, then click "Change". Under "Member of", select "Domain" and type your domain name (for example, "company.local"). Click "OK". Windows will prompt you for a domain administrator username and password — use the account you logged in with on the domain controller.
Windows will contact the domain controller, verify your credentials, and add the computer to the domain. You will be asked to restart. After the restart, you can log in with a domain account instead of a local account. The domain controller now manages this computer's login and permissions.
Frequently Asked Questions
Can I install Active Directory on Windows 11 Pro?
No. Active Directory is only available on Windows Server editions. Windows 11 Pro does not include the Active Directory Domain Services role, and Microsoft does not offer it as a separate download. You must use Windows Server 2022, 2019, or 2016.
What is the difference between Windows Server 2022 and 2019 for Active Directory?
Both support Active Directory fully. Windows Server 2022 is newer and receives longer support from Microsoft, but 2019 works just as well for small networks. Choose 2022 if you are setting up a new domain. If you already have 2019 running, there is no reason to upgrade.
Do I need a physical server or can I use a virtual machine?
A virtual machine works fine for testing or small networks. Use Hyper-V on Windows 11 Pro or VirtualBox (free) on any Windows 11 edition. For production networks with many users, a physical machine is more reliable, but virtual machines are common in small offices.
What happens if I forget the DSRM password?
You will not be able to boot into Directory Services Restore Mode to fix Active Directory problems. Write down the password and store it securely before you finish the promotion wizard. If you forget it, you will need to reinstall Windows Server and Active Directory from scratch.
Can I have more than one domain controller?
Yes. After your first domain controller is running, you can promote additional Windows Server machines to domain controllers in the same domain. This provides redundancy — if one goes down, the others keep the domain running. Add the second server to the domain first, then promote it using the same wizard, but select "Add a domain controller to an existing domain" instead of "Add a new forest".