Which Feature Manages AD Password Policies on a Member Server?

You have an Active Directory Domain Services (AD DS) domain. The domain contains a member server named Server1 that runs Windows Server. You need to ensure that you can manage password policies for the domain from Server1. Which command should you run first on Server1?

  1. Install-WindowsFeature RSAT-AD-Tools
  2. Install-WindowsFeature RSAT-ADRMS
  3. Install-WindowsFeature GPMC Source Reference Answer
  4. Install-WindowsFeature RSAT-AD-PowerShell

Community Votes

C
53%
A
47%

53% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the dependency between AD password configuration and GPO management, trapping candidates who overlook that password policies reside exclusively within Group Policy frameworks.

Domain password policies are enforced through Group Policy Objects (GPOs), making the Group Policy Management Console (GPMC) a mandatory prerequisite for remote configuration. Exam candidates must recognize that Windows Server requires explicit feature installation to access these administrative tools.

Option A (RSAT-AD-Tools) is frequently chosen due to its popularity on client OSes, but it is not the optimal or supported method for installing management consoles on Windows Server roles.

Community Discussion (12 comments)

sardonique 👍 7
Rsat-AD-Tools include the following tools: RSAT-AD-PowerShell RSAT-ADLDS and RSAT-ADDS, which has within it RSAT-AD-AdminCenter RSAT-ADDS-Tools so if you install Rsat-AD-Tools you have pretty much everything you need, except GPMC which you might need to configure the GPOs, and the domain wide password settings. As always, the questions are ambiguous and dishonest made by frustrated guys with the purpose to set you up for failure.
formacionproxya 👍 1 Selected: D
We only need RSAT-AD-PowerShell to define and assign Fine-Grained Password Policies, to manage passwords policies.
NoMedi 👍 1 Selected: A
While the Group Policy Management Console (GPMC) is indeed a tool that can be used to manage password policies, it is not the most comprehensive option for this specific task. The GPMC is primarily used for managing Group Policy Objects (GPOs), including the Default Domain Policy where the domain-wide password policy is typically configured. However, installing only the GPMC would not provide all the necessary tools for comprehensive password policy management, especially when it comes to more advanced features like Fine-Grained Password Policies (FGPP)
Ni_yot 👍 1 Selected: A
A appears correct. After these conflicting comments i decided to use chatgpt and the answer is interesting. By installing RSAT and using the Group Policy Management Console, you can effectively manage password policies for your Active Directory domain from Server1. Since its a member server you install RSAT first, then GMPC
Ksk08 👍 1
A is correct you have to install Install-WindowsFeature RSAT-ADDS before you can Install-WindowsFeature GPMC. The question is asking which one to perform first for the task
mhmyz 👍 1 Selected: C
Rsat-AD-Tools not support Windows Server and not include GPO management tool.
Krayzr 👍 3 Selected: A
A. Install-WindowsFeature RSAT-AD-Tools. The RSAT-AD-Tools feature includes command-line tools for managing Active Directory Domain Services (AD DS). These tools help you manage domains, users, and computers, effectively allowing you to manage password policies for the domain. Here’s why the other options are not the best choices: C. Install-WindowsFeature GPMC: This command installs the Group Policy Management Console. While GPMC is used to manage Group Policies, it is not specifically required to manage password policies from a member server. Remember, after installing the RSAT-AD-Tools feature, you can use the Group Policy Management Console or Active Directory Administrative Center to manage password policies. You can also use PowerShell commands to manage password policies.
AK_1234 👍 2
Answer C
SIAMIANJI 👍 2 Selected: C
Group Policy Management Console
IcE 👍 2 Selected: C
Group Policy Management Console (GPMC)
DATS720 👍 3 Selected: C
C: You need to edit a GPO for this. You need GPMC.
pnewcap 👍 2 Selected: A
A I GUESS

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Active Directory domain password policies are stored and modified within Group Policy Objects, specifically the Default Domain Policy or Fine-Grained Password Policies. To edit these policies from a member server, you must first deploy the Group Policy Management Console (GPMC). Running Install-WindowsFeature GPMC provisions the necessary MMC snap-ins and PowerShell modules, enabling full GPO lifecycle management without relying on client-side toolsets.

Why the Other Options Are Wrong

RSAT-AD-Tools (Option A) and RSAT-AD-PowerShell (Option D) are primarily optimized for Windows client operating systems and focus on AD object manipulation rather than GPO editing. Even if RSAT features were installed, they do not automatically provision the GPMC interface required for policy configuration. Option B installs Rights Management Services, which handles encryption and access control, completely unrelated to authentication or password standards.

Community Comment Notes

The voting split between A and C reflects real-world ambiguity, but official Microsoft guidance prioritizes GPMC for server environments. Comment [3] and [4] correctly highlight that GPMC is non-negotiable for editing password-related GPOs. Several users noted that RSAT meta-packages are unnecessary when Windows Server supports direct feature deployment, aligning with the exam's expected workflow.

Official Reference

Exam Strategy

Map every AD configuration task to its underlying architectural component before selecting installation commands. When dealing with Windows Server roles, prioritize native Install-WindowsFeature targets over client-focused RSAT bundles to avoid dependency traps.

Related Analysis

← Back to AZ-800 Study Guide