Which Feature Manages AD Password Policies on a Member Server?
You have an Active Directory Domain Services (AD DS) domain. The domain contains a member server named Server1 that runs Windows Server. You need to ensure that you can manage password policies for the domain from Server1. Which command should you run first on Server1?
Community Votes
53% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the dependency between AD password configuration and GPO management, trapping candidates who overlook that password policies reside exclusively within Group Policy frameworks.
Domain password policies are enforced through Group Policy Objects (GPOs), making the Group Policy Management Console (GPMC) a mandatory prerequisite for remote configuration. Exam candidates must recognize that Windows Server requires explicit feature installation to access these administrative tools.
Option A (RSAT-AD-Tools) is frequently chosen due to its popularity on client OSes, but it is not the optimal or supported method for installing management consoles on Windows Server roles.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Active Directory domain password policies are stored and modified within Group Policy Objects, specifically the Default Domain Policy or Fine-Grained Password Policies. To edit these policies from a member server, you must first deploy the Group Policy Management Console (GPMC). RunningInstall-WindowsFeature GPMC provisions the necessary MMC snap-ins and PowerShell modules, enabling full GPO lifecycle management without relying on client-side toolsets.Why the Other Options Are Wrong
RSAT-AD-Tools (Option A) and RSAT-AD-PowerShell (Option D) are primarily optimized for Windows client operating systems and focus on AD object manipulation rather than GPO editing. Even if RSAT features were installed, they do not automatically provision the GPMC interface required for policy configuration. Option B installs Rights Management Services, which handles encryption and access control, completely unrelated to authentication or password standards.Community Comment Notes
The voting split between A and C reflects real-world ambiguity, but official Microsoft guidance prioritizes GPMC for server environments. Comment [3] and [4] correctly highlight that GPMC is non-negotiable for editing password-related GPOs. Several users noted that RSAT meta-packages are unnecessary when Windows Server supports direct feature deployment, aligning with the exam's expected workflow.Official Reference
Exam Strategy
Map every AD configuration task to its underlying architectural component before selecting installation commands. When dealing with Windows Server roles, prioritize native Install-WindowsFeature targets over client-focused RSAT bundles to avoid dependency traps.