Install AD Pro Toolkit Browser

This guide shows you how to install AD Pro Toolkit Browser on a server and get your team signed in.

Before you start

  1. Check the requirements first. You can install it on a desktop but the recommendation is to install it on a server that everyone can pull up in a browser.
  2. Managed Service Accounts (sMSA and gMSA) are supported. You must use the advanced setup wizard to configure the app to use a managed service account. See the Managed Service Account Configuration section for steps.

How it is deployed

The browser build installs once, on one server, and everyone else uses it from a browser. That is the main difference from the desktop build, which is installed on each administrator's own machine.

The host runs two things:

  • The web application, which is what people sign in to.
  • A sync service, which reads from Active Directory on a schedule and keeps a local copy for reports to run against.

Reports read that local copy rather than querying a domain controller each time, which is what keeps them fast on a large directory. Nothing is installed on your domain controllers, and nothing is installed on the machines of the people using it.

Local System account (default)

This is the default install method, this will configure the service to use the local system account and you then must enter a username and password to connect to Active Directory.

Step 1 - Install steps

  1. Download ADProToolkit.exe from the download page.
  2. Run the installer
  3. On the welcome screen, click Next.
  4. Accept the End User License Agreement and click Next.
  5. Choose the install folder and click Next.
  6. Click Install. Windows User Account Control may prompt for elevation. Click Yes. The installer is digitally signed, so it shows a verified publisher.
  7. When it finishes, click Finish. A shortcut is added to your desktop.
  8. You can access the app on another computer by using the URL http://HOSTNAME:8083 (replace hostname when the hostname of your computer)

Step 2 - First Run Configuration

On first run you will get a configuration wizard

  1. On the connect screen enter your Active Directory domain name, username and password. This will be the account the app uses to connect to active directory. Click Test connection to verify it works.
  2. On the access page add users or groups that you want to grant access to. By default it grants the user installing the app super admin access.
  3. On the sync screen it should automatically start syncing.
  4. Click Finish

Managed Service Account Configuration

This configuration will set the service to run as a managed service account and requires no additional username or password to connect to Active Directory.

Step 1 - Create Managed Service Account

The app does not create the service account so you need to create and enable it first.

  1. Run this command to create a managed service account. Change SERVICE-ACCOUNT-NAME to the name you want for example ADProToolkitSvc.
New-ADServiceAccount -name "SERVICE-ACCOUNT-NAME" -RestrictToSingleComputer
  1. Run this command to enable the service account on the computer. Change HOSTNAME to the name of the computer where AD Pro Toolkit is installed.
Add-ADComputerServiceAccount -Identity "HOSTNAME" -ServiceAccount "ADProToolkitSvc"
  1. Run this command on the computer where AD Pro Toolkit is installed.
Install-ADServiceAccount -Identity "SERVICE-ACCOUNT-NAME"
  1. To test that the service account is installed correctly run this command on the computer. It should return True.
Test-ADServiceAccount -Identity "ADProToolkitSvc"

Step 2 - Run Advanced Setup Wizard

  1. Run the AD Pro Toolkit Advanced Setup, shortcut is in start menu.
  2. Select Managed service account then enter the managed service account name. The service account name must end in a $.
  3. On the connect screen enter your domain and click test connection.
  4. On the access screen enter the user or group who should have admin access.
  5. On the review screen click Finish. The wizard will now configure the service to run as the managed service account.

Using it

Access the application in a browser at http://HOSTNAME:8083, where HOSTNAME is the server you installed it on. There is nothing to install for them.

If SSL is enabled it will be https://HOSTNAME

Any current version of Chrome, Edge, Firefox or Safari works. The interface is a standard web application and does not need a particular browser.

Access is controlled by role. Roles are scoped, so somebody can be given group management over a single organizational unit rather than over the whole directory, and one account can hold more than one role.