β‘ Windows AD Remote Administration Control Center β Enterprise Remote Control & Administration Suite
Created & Developed by Askarali Mattummal (LinkedIn | GitHub | Telegram)
A high-performance, 100% agentless Windows & Active Directory remote management, screen mirroring, diagnostics, and IT helpdesk suite.
As a systems engineer managing active enterprise Active Directory environments, I frequently found myself frustrated by the constant friction of daily IT administration. Performing routine support tasks meant constantly switching between a dozen separate tools:
- Opening Active Directory Users & Computers (ADUC) just to unlock an account or check a user's department and group memberships;
- Launching multiple MMC snap-ins (Computer Management, Services, Event Viewer, Print Management);
- Opening command prompts for
shadow.exe,net use,ipconfig,gpupdate, or PowerShell remoting; - Relying on heavy, commercial remote support tools that require background client services, third-party cloud relays, and expensive recurring licenses.
To solve this, I originally designed and built Windows AD Remote Administration Control Center as my own personal, all-in-one administrative workstation console. My goal was simple: a single, blazing-fast, lightweight, portable executable (~580 KB) that connects directly to domain computers using native Windows protocols (LDAP, WMI, RPC, SMB, Terminal Services) with zero external dependencies and zero agents to install.
This suite was crafted specifically for IT professionals, including:
- Active Directory & Windows Domain Administrators managing enterprise domain workstations and servers.
- Systems Engineers & Network Administrators needing fast remote diagnostics, live hardware telemetry, IP configuration, and event log auditing.
- IT Helpdesk & Desktop Support Specialists who need to shadow user sessions instantly, reset passwords, clear print queues, and clean temporary junk without interrupting users.
- Managed Service Providers (MSPs) who want a 100% portable, agentless tool that runs from a USB flash drive or secure administrative share.
After colleagues and fellow sysadmin friends used the tool and experienced how much time it saved them daily, they urged me to release it publicly. I decided to publish this project so that the wider IT administration community can benefit from it freely.
Important
The only official and authentic release source for this project is:
π https://github.com/SuperUser-exe/Windows-Active-Directory-Remote-Administration-Control-Center
- Latest Official Release: Version 2.6.5 is the current official public release. Next-generation features (such as Desktop Info HUD, God Mode, and Idle Agent Service) are in active testing and coming soon in v2.7.0.
- Do not trust unofficial copies: If downloaded from third-party sites, file-sharing platforms, or re-hosted mirrors, the author assumes no responsibility for modified, corrupted, or repackaged binaries.
- Integrity Check: Always verify the official release SHA-256 checksums provided in
CHECKSUMS.txt. - Community & Discussions: We have enabled GitHub Discussions! Come say hello, share workflow feedback, report issues, or suggest new features.
- Telegram Community Chat: Join our active Telegram group at t.me/WADRACC for instant community chat, direct feedback, updates, and IT discussions.
Most remote management tools (RMMs) and commercial support platforms force you to install bloated background services on every single computer, set up complex web portals, configure SQL databases, or pay exorbitant monthly subscriptions per endpoint.
Windows AD Remote Administration Control Center works on a fundamentally different, ultra-lightweight architectural principle:
- 100% Agentless & Fully Portable: No client software, drivers, or background services are ever installed on managed endpoints. Everything runs on-demand from a single, self-contained portable executable (~600 KB).
- Background In-Memory Management Engine: Under the hood, the application executes pure, native Windows management protocolsβreading and modifying system properties, LDAP directories, and Windows management APIs directly in memory.
- Zero Foreign Binaries or Residual Payloads: There are no temporary batch scripts, remote agents, or third-party background daemons left behind on client computers.
- Direct RDS Screen Shadowing: Hooks directly into built-in Windows Terminal Services (
query.exe session+mstsc.exe /shadow), allowing IT administrators to mirror and control user screens in real-time with zero latencyβwithout kicking users off, disturbing their session, or locking their screen.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Windows AD Remote Administration Control Center β
β Single Standalone Portable Executable β
β Native C# / WPF + In-Memory Windows APIs β
βββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββ
βΌ βΌ βΌ
βββββββββββββββββββββββββ βββββββββββββββββββββββββ βββββββββββββββββββββββββ
β Active Directory β β Workstation & WMI β β Remote Desktop / β
β (LDAP / ADSI Layer) β β (CIM & Registry Layer)β β Terminal Services β
βββββββββββββ¬ββββββββββββ βββββββββββββ¬ββββββββββββ βββββββββββββ¬ββββββββββββ
β Reads / Writes Direct Attributes β Remote Management Pipelines β Native Shadow & RDP
βΌ βΌ βΌ
βββββββββββββββββββββββββ βββββββββββββββββββββββββ βββββββββββββββββββββββββ
β β’ User Objects & OU β β β’ System Processes β β β’ query.exe session β
β β’ Account Lockouts β β β’ Windows Services β β β’ mstsc.exe /shadow β
β β’ Password Resets β β β’ Remote Printers β β β’ Instant Screen Mirr β
β β’ 40+ User Attributes β β β’ Remote Registry β β β’ No-Kickoff Control β
βββββββββββββββββββββββββ βββββββββββββββββββββββββ βββββββββββββββββββββββββ
- Direct Domain Controller Queries: Communicates directly with domain controllers using native directory services over secure LDAP/Kerberos.
- Real-Time Attribute Inspection: Reads user properties dynamically (
lockoutTime,badPwdCount,userAccountControl,pwdLastSet,memberOf, contact metadata, hierarchy). - Instant Account Unlocking & Resets: Unlocks accounts immediately, or triggers secure password resets natively without requiring RSAT on the technician's workstation.
- Live Hardware Telemetry: Queries hardware specifications, active processes, system services, and installed software directly from client systems.
- Per-Printer Queue Management: Enumerates printer drivers and inspects remote print jobs, clearing hung documents with precision without affecting other printers.
- Cross-Profile Software & Drive Auditing: Inspects system uninstall records and queries all loaded user profiles in
HKEY_USERSto discover per-user apps (Teams, Zoom, VS Code) and mapped network drives (Ctrl + D) even when remote users are idle. - Dynamic Profile Path Resolution: Dynamically discovers the active user's physical profile directory on disk, ensuring wallpaper changes and telemetry overlays apply correctly across all user sessions.
- Console Session Discovery: Uses native Windows
query.exe sessionto instantly detect the logged-in user's active console or RDP session ID. - Zero-Lag Hardware Screen Control: Launches native Microsoft
mstsc.exe /shadow:<id> /control /noConsentPromptfor zero-lag, hardware-accelerated remote control without installing third-party VNC servers or display capture drivers.
- β‘ Sub-Second Cold Startup & Telemetry Persistence: High-speed caching engine with 24-thread parallel network endpoint scanning; hydrates and verifies 40+ endpoints with real-time green/red statuses and active user accounts in under 1.5 seconds.
- π Dedicated Quick Assist Remote Assistance Button: 1-Click launcher for Microsoft Quick Assist positioned in the primary bottom connection bar, featuring the official Microsoft Fluent Quick Assist icon embedded locally as an offline resource (100% functional in air-gapped environments).
- β±οΈ Dedicated Live Uptime Column & Duration Intelligence: Real-time system uptime column in main inventory grid with instant 1-click numerical sorting by total uptime duration, health color thresholds (green for active, amber for >30 days without reboot), and exact last boot tooltip. Decomposes idle and lock durations into clean, human-readable lowercase units (
13m,1h 30m,15h 16m,17h,1d 4h,1mo 2d). - β±οΈ Inactivity & Idle Monitor Agent in Top Bulk Actions: 1-Click mass deployment and removal of the endpoint activity monitor directly from the top Bulk Actions bar (
β±οΈ Idle Agent). Features intelligent skip logic for already-installed hosts, targeted retries for failed/unreachable hosts, dynamic button toggle toRemove Monitorwhen all hosts are active, rich tooltips, and granular diagnostic logging ([SUCCESS],[SKIPPED],[NO ACCESS],[OFFLINE],[FAILED],[ERROR]). - π‘οΈ System-Level Windows Service & 24/7 Presence Monitoring: Deployed to the system-managed directory, the agent operates as a native Windows Service starting automatically at Windows boot before any user logs in. It monitors continuous presence 24/7 across all lifecycle states: pre-logon, Windows login screen, active sessions, user lock, user switching, multi-user sign-in/sign-out, and system shutdown. Fully hardened with strict file permissions, hidden from Installed Apps, and protected against unauthorized termination in Task Manager.
- π 1-Minute Lightweight Silent Background Refresh: Background telemetry engine automatically refreshes Online/Offline status, ping latency, Logged-in User, Active/Idle presence states (
π’ Active,π€ Idle (1h 30m),π Locked (15h 16m),πͺ Logged Off,π΄ Offline), and Idle Agent presence every 60 seconds with an atomic concurrency guard, without clearing the grid or interrupting user typing and selection. - π¬ Advanced Remote User Messaging Hub: Enforce exact character limits, Title/Subtitle/XL modes with contextual Large Text font toggle, non-clipping cards, and vibrant multi-icon badge containers.
- π¨οΈ Remote Shared & Network Printer Infrastructure Manager: Modern in-window loading splash overlay with live progress, parallel asynchronous query engine, live queued jobs column distinguishing active spooler documents (
β οΈ {N} Pending) from historical logs (0), and domain print server test page dispatch. - π₯ Active Directory Group Membership Manager: Live interactive security group management (Add to Group, Remove from Group, Refresh) with built-in primary group safeguards directly from the Profile Card.
- β‘ Instant Screen Shadowing: Mirror remote user displays without disconnecting or logging them off.
- π Modern Pre-Shadow Alerts: Transmits unobtrusive Action Center Toast notifications near the system clock with sound chimes.
- π Remote Startup Applications Manager: Inspect and manage machine and per-profile startup programs, toggle Enable / Disable without deleting entries (
π Startup). - π₯ Local Computer Users & Accounts Manager: Agentless local account managementβprovision users, reset passwords, and toggle active status (
π₯ Local Users). - π Sub-Second Real-Time Live Performance Monitor: High-frequency CPU, RAM, Network (RX/TX), Disk I/O telemetry with historical sparklines and hardware specs (
π Live Perf). - π Remote Network & IP Configuration Hub: Switch DHCP β Static IP remotely, flush DNS, release/renew lease, and safe adapter restart (
π IP Config). - π Remote Workstation Lock & Unlock Controller: Real-time lock screen detection, session locking, console reconnect, and direct session unlock.
- ποΈ Remote Mapped Drives Manager: Inspect, add, edit, and disconnect mapped network drives across all remote user profiles with live storage gauges (
Ctrl + D). - π» Interactive Remote Terminal: Agentless CMD & PowerShell execution with instant preset commands (
whoami,gpupdate,sfc,ipconfig). - π» Graphical Specs Dashboard: Visual sensor cards with progress gauges for CPU, RAM, Disk usage, BIOS Serial Number, and Uptime.
- π¦ Full Software Inventory: Dual-engine scanning across
HKLM(64-bit & 32-bit) and allHKEY_USERSprofiles with silent 1-click uninstaller. - π Advanced Event Log Viewer: High-speed reverse streaming of System and Application event logs with vivid severity color badges and date range filters.
- π¨οΈ Remote Printers & Queue Manager: Inspects local and domain print server shared printers with live print job management.
- π€ Active Directory User Controls: Dynamic account lockout detection with 1-click unlocking and password resets.
- π§Ή 4-Path Deep Temp Cleaner: Purges Temp, AppData Temp across all profiles, Recent files, and Prefetch in 1-click with byte counters.
- π₯οΈ Desktop Info HUD (Sysinternals BgInfo Engine): Directly stamp system telemetry onto desktop wallpapers in 2 crisp columns with drop shadows, or launch an optional floating widget (
π₯οΈ HUD (BgInfo)). - πΌοΈ Remote Desktop Wallpaper Changer & Manager (Single & Bulk): Remotely apply custom background images (JPG, PNG, BMP) across one or multiple remote PCs with display fit styles (Fill, Fit, Stretch, Tile, Center, Span), live image preview, and 1-click original backup restoration.
- π Windows God Mode & Power Tweaks Hub (Single & Bulk): Enable or remove Windows Master Control Panel on User & Public Desktop, context menus, and direct admin launcher, plus 1-click power tweaks (Take Ownership, Classic Win11 Menu, Ultimate Performance, CompactOS, Show File Extensions, Disable Telemetry, 1-Click RDP Enable, Disable Bing Search) across single or multiple remote computers.
- π― Dynamic Smart Context Menu (Single vs Bulk): Right-clicking multi-selected computers dynamically displays only bulk-supported actions (Wallpaper, God Mode, HUD, Idle Agent, Deep Clean, GPUpdate, Deployer, File Push, Messaging, Power & WOL). Right-clicking a single computer presents the full administrative console with informative messages when features are not configured or supported.
- π Remote Browser URL & File Launcher: Launch web URLs in Default Browser, Microsoft Edge, or Google Chrome directly inside the remote user's interactive session.
- π Seamless In-App Auto-Updater: Directly updates the application in-place from GitHub Releases without browser redirects or installer wizards!
- β¨οΈ Universal Keyboard Ergonomics: Dismiss any popup window with
ESC, open Drive Manager withCtrl + D.
| Category | Features & Capabilities |
|---|---|
| π Remote Assistance | β’ Dedicated Quick Assist Button β’ Positioned after Shadow Session and before RDP in primary bottom action bar β’ Authentic Microsoft Fluent Quick Assist icon embedded locally (100% offline-ready) β’ Instant 1-click launch of quickassist.exe / ms-quick-assist: without needing Ctrl+Win+Q |
| β±οΈ Live Uptime & Durations | β’ Dedicated Live Uptime Column: Displays real-time endpoint uptime (β±οΈ 3d 12h, β±οΈ 18d 6h, β±οΈ 1mo 5d) with 1-click numerical sorting by total duration, health color thresholds (green for normal, amber for >30d overdue reboot), and exact last boot tooltip (Last Boot: yyyy-MM-dd HH:mm)β’ Smart Duration Decomposition: Automatically scales idle and lock durations into clean, compact lowercase units ( m, h m / h, d h / d, mo d / mo) eliminating confusing raw minute counts (e.g. Idle (916m) -> Idle (15h 16m), Locked (1020m) -> Locked (17h)) |
| β±οΈ Idle & Presence | β’ Inactivity / Idle Monitor Agent in Top Bulk Actions β’ Real-time workstation state detection: π’ Active, π€ Idle (...), π Locked (...), πͺ Logged Off, π΄ Offline with human-readable duration formatting (m, h m, d h, mo d)β’ Continuous 24/7 lifecycle monitoring: Starts at Windows boot before user login, monitors Windows login screen, active sessions, user switching, logout, and shutdown β’ Native Windows Service ( ADRC_IdleMonitor) installed under %SystemRoot%\System32\ADRemoteControl\ADRC_IdleAgent.exe with runtime data in %ProgramData%\ADRemoteControl\idle.jsonβ’ Privacy-friendly: Monitors user idle time without keystroke logging or screen recording β’ Smart mass parallel deployment and 1-click bulk uninstaller ( Remove Monitor)β’ Intelligent skip logic (skips installed hosts) & targeted retry for failed/unreachable hosts β’ Enterprise Tamper Protection: Hidden from Programs & Features / Installed Apps, strict file permissions lockdown, eliminated from Task Manager Startup Apps, and native process tamper protection preventing standard user process termination in Task Manager β’ Structured diagnostic logging ( [SUCCESS], [SKIPPED], [NO ACCESS], [OFFLINE], [FAILED], [ERROR]) |
| π Auto Refresh | β’ 1-Minute Lightweight Silent Background Refresh Engine β’ Automatically executes every 60 seconds across all listed computers β’ Atomic concurrency guard prevents overlapping/colliding scans β’ Fast network connection checks on dedicated background threads β’ Refreshes Online/Offline, Ping latency, Logged-in User, Active/Idle status, and Idle Agent presence silently without clearing the grid or interrupting user typing |
| π― Smart Context Menu | β’ Dynamic Context Menu Architecture (Single vs Multi-Device) β’ Automatically detects multi-selection to show only bulk-compatible operations β’ Protects against accidental single-host tool execution in bulk β’ Full rich menu on single selection with clean "Not Configured / Not Supported" feedback on hardware or policy limitations (Battery, BitLocker, LAPS) |
| π₯οΈ Remote Display | β’ Remote Shadowing (Attended & Auto-Attended /noConsentPrompt)β’ Full Control (Keyboard & Mouse) or View-Only β’ Fullscreen & Multi-Monitor spanning β’ Standard RDP & Server Console Admin ( /admin) sessions |
| π User Alerts | β’ Action Center Toast Notifications near the taskbar clock β’ Audio chime notification β’ Automated fallback to msg.exe |
| π God Mode & Tweaks | β’ Windows God Mode (Master Control Panel) Remote Controller (Single & Bulk) β’ Deploy/remove God Mode folder shortcut on User & Public Desktop β’ Native desktop background right-click context menu integration β’ 1-Click live interactive launch of God Mode Master Control Panel on remote user's screen β’ "Take Ownership" context menu injector to reclaim permissions on locked folders β’ Classic Windows 11 Context Menu restorer (bypasses "Show more options") β’ "Ultimate Performance" power plan activator for maximum hardware throughput β’ CompactOS storage compression (free 3-5 GB on SSD) β’ Disable Consumer Bloatware & promotional tiles β’ Always Show File Extensions & Hidden Files in Explorer β’ Disable Windows Diagnostic Telemetry for enterprise privacy and compliance β’ 1-Click Enable Remote Desktop (RDP), NLA & Firewall β’ Disable Bing Web Search in Start Menu |
| πΌοΈ Wallpaper Changer | β’ Remote Desktop Wallpaper Changer & Manager (Single & Bulk) β’ Remotely apply custom corporate wallpaper (JPG, PNG, BMP) to single or multi-selected computers β’ Fit styles: Fill (Default), Fit, Stretch, Tile, Center, Span β’ Embedded in-app image preview before applying β’ Automatic backup of original wallpaper prior to replacement β’ 1-Click restore original wallpaper on single or bulk target computers β’ Seamless updates across active console and RDP user sessions |
| π₯οΈ Desktop Info HUD | β’ Sysinternals BgInfo Wallpaper Engine (π₯οΈ HUD (BgInfo))β’ Direct-to-wallpaper stamping matching classic Sysinternals BgInfo β’ Two-column telemetry with drop shadows for 100% legibility on any wallpaper β’ 3 deployment modes: Wallpaper Overlay, Floating HUD Widget, or Both β’ Dynamic profile path discovery β’ Theme-accurate live preview and 1-click wallpaper restoration |
| π Browser & App Run | β’ Remote Browser URL & Program Launcher β’ Launch URLs in Default Browser, Microsoft Edge, or Google Chrome β’ Non-interactive execution directly inside user session |
| π Startup Apps | β’ Remote Startup Applications & Autoruns Manager (π Startup)β’ Machine and per-user profile startup enumeration β’ Dynamic Enable / Disable toggling without registry deletion β’ Preserves user configurations β’ 1-Click delete orphaned autorun entries and CSV export |
| π₯ Local Users | β’ Local Computer Users & Accounts Manager (π₯ Local Users)β’ Works without active logon session (direct local accounts connection) β’ Account type badging: π Administrator, π€ Standard User, πΌ Guest β’ Remote user creation, password reset, and enable/disable toggle |
| π Live Monitor | β’ Sub-Second Live Performance Monitor (π Live Perf)β’ high-frequency CPU, RAM, Network (RX/TX), Disk active I/O β’ 60-second historical sparkline graphs & performance charts β’ Motherboard DIMM module slot inspector (DDR4/DDR5, MHz, part numbers) β’ Physical storage drives, link speeds, and network adapter telemetry |
| π Network & IP Hub | β’ Remote Network & IP Configuration Hub (π IP Config)β’ Remote DHCP β Static IPv4 switching with format validation β’ Remote ipconfig /flushdns, /registerdns, /release, /renewβ’ Safe network adapter reset script with automatic re-enable |
| π Lock & Unlock | β’ Workstation Lock & Unlock Controller (π Lock Screen)β’ Real-time lock screen state detection and session telemetry β’ Remote workstation lock, console session reconnect, and direct session unlock β’ Embedded live diagnostic execution console |
| ποΈ Network Drives | β’ Remote Mapped Network Drives Manager (Ctrl + D)β’ Dual-engine inspection across registry and active mounted network disks β’ Real-time storage capacity gauge (Free / Total GB) β’ 1-Click Add Drive Mapping with automatic free letter selection (Z-D) & UNC test β’ Edit Mapping and modify persistence (Reconnect at sign-in) β’ Disconnect & Remove mapping from registry and active session β’ 1-Click Explorer launcher into remote UNC share |
| π» Remote Terminal | β’ Interactive command console (CMD & PowerShell) β’ 1-click presets: whoami, gpupdate /force, ipconfig /all, sfc /scannow, pingβ’ Output logging and clipboard export |
| π» Diagnostics | β’ Visual sensor dashboard with CPU, RAM, and Disk storage gauges β’ Motherboard, BIOS, Serial Number / Dell Service Tag inspection β’ System boot timestamp and continuous uptime health tracker |
| π Processes & Services | β’ Remote Task Manager: view processes, memory usage, terminate hung apps β’ Windows Services Controller: query status, Start, Stop, Restart services β’ 1-Click Remote Print Spooler restart |
| π¦ Software Inventory | β’ Dual-engine scanner across machine and all user profiles β’ Discovers per-user apps: Teams, Zoom, Slack, WhatsApp, Canva, VS Code β’ Native fallback when RemoteRegistry service is disabledβ’ 1-click silent remote uninstaller for MSI and EXE packages |
| π Event Log Viewer | β’ Reverse-chronological streaming to load newest events first β’ Vivid color badges for Critical, Error, Warning, Information β’ Date range filter: All Dates, Today Only, Last 24h, Last 7d, Last 30dβ’ One-click presets: Reboots (1074), Shutdowns (6006), Power Loss (41/6008), BSOD (1001), App Crashes (1000), Service Crashes (7031), Disk/NTFS errors |
| π¨οΈ Printer Management | β’ Inspect local printers and domain print server shared printers β’ Accurate active user default printer detection ( β Default) via remote registryβ’ Real-time Test Print ( π¨οΈ Test Print) executionβ’ Live Pending Jobs column cross-referenced with active queue β’ Real-time queue inspection: Document, Owner, Pages, Size, Submission Time β’ 1-Click Cancel Job, Purge All Jobs, and Restart Spooler |
| π File Explorer | β’ 1-Click Explorer access into \\<host>\C$β’ Direct navigation to remote user's Desktop, Downloads, and Documents |
| π€ AD Account Actions | β’ Enterprise 360Β° AD User Profile Inspector & In-App Editor: 40+ directory attributes, organizational hierarchy, contact information, and security group memberships β’ βοΈ Edit AD User Profile Attributes: In-place editing of First/Last/Display Name, Title, Department, Company, Office, Phone, Mobile, Email, and Address with direct LDAP commit β’ π Edit / Set Computer Description: Live Active Directory computer description updater synchronized to the computer grid β’ Real-time lockout detection: button turns red ( β οΈ Account Locked)β’ 1-click AD account unlocking β’ Remote password reset with optional forced password change at next logon |
| π§Ή Deep Temp Cleaner | β’ Purges 4 administrative paths: C:\Windows\Temp, User AppData\Local\Temp, Recent files across all profiles, and Prefetchβ’ Reports exact file count and MB disk space freed |
| β‘ Power Management | β’ Wake-on-LAN (WOL) magic packets β’ Lock remote screen without logging off β’ Graceful remote user session logoff β’ Remote reboot and shutdown with 5-second countdown |
| π Audit Logging | β’ Reverse-chronological activity log (newest records always on top) β’ Isolated single-machine audit filtering β’ Outcome logging: SUCCESS, FAILED, CANCELLED with error messages |
| π Auto-Updater | β’ Direct GitHub Releases API integration with SuperUser-exe/Windows-Active-Directory-Remote-Administration-Control-Centerβ’ In-app release notes viewer β’ In-place download, detached update script, and automatic restart (0 browser redirect!) |
- Quick Filter / Search Box (
Ctrl+S/Ctrl+F): Real-time filter box that narrows the inventory list instantly as you type. Searches across Computer Names, IP Addresses, Logged-in Users, Descriptions, Operating Systems, and OUs. PressingESCclears the filter. π Refresh AD / Scan(F5/Ctrl+R): Re-synchronizes computer inventory from Active Directory Domain Services and triggers a 24-thread parallel network status and ping latency check.π Updates: In-app GitHub Release monitor. Compares current version with the latest release, displays formatted changelogs, and performs a 1-click in-place update and restart in ~1.5 seconds without opening a browser.βΉοΈ Usage Guide: In-app operator reference manual with searchable tabs, copy, and export features.π Activity Log: Reverse-chronological audit trail of all administrative actions. Records timestamp, operator, target host, action, and detailed outcome status (SUCCESS,FAILED,CANCELLED).π Theme Toggle: Instantly switches between high-contrast Dark Mode and Light Mode with zero visual glitching.π¬ Feedback: In-app star rating and suggestion submission dialog allowing operators to submit 1 to 5 star ratings, bug reports, or feature suggestions with instant transmission.π¬ Community / Telegram: Direct link to the official Telegram community chat (t.me/WADRACC) for support and feedback.
Located directly above the computer inventory grid, these actions operate concurrently across all multi-selected computers (or all listed computers if none are explicitly selected):
πΌοΈ Wallpaper: Mass-deploy custom corporate desktop wallpapers (Fill, Fit, Stretch, Tile, Center, Span) with embedded image preview and 1-click backup restoration.π God Mode: Mass-deploy or remove the Windows God Mode shortcut on user and public desktops, and toggle 10+ enterprise system power tweaks.π₯οΈ HUD (BgInfo): Mass-stamp system telemetry onto desktop wallpapers in Sysinternals BgInfo style, or deploy floating companion widgets.β±οΈ Idle Agent/Install Monitor/Retry Monitor/Remove Monitor:- 1-Click Mass Service Deployment: Installs the monitoring agent as a system-level Windows Service (
ADRC_IdleMonitor) with automatic boot-time startup (start= auto). - Continuous 24/7 Presence Monitoring: Starts with Windows during system boot before any user logs in; tracks presence across login screens, active user sessions, lock/unlock, user switching, and system shutdown.
- Intelligent Skip: Inspects target endpoints and automatically skips computers where the service is already installed and healthy.
- Targeted Retry: Automatically re-targets only failed, offline, or inaccessible machines on subsequent clicks.
- Dynamic Toggle to Uninstaller: When 100% of endpoints are monitored, button dynamically transitions to
Remove Monitorfor 1-click bulk cleanup. - Granular Diagnostic Logging: Every machine logs an itemized status code (
[SUCCESS],[SKIPPED],[NO ACCESS],[OFFLINE],[FAILED],[ERROR]).
- 1-Click Mass Service Deployment: Installs the monitoring agent as a system-level Windows Service (
π§Ή Deep Clean: Concurrently purges Temp, User Temp across all profiles, Recent, and Prefetch on all target endpoints.π GPUpdate: Executes backgroundgpupdate /forcein parallel across targets.π¦ Deployer: Silent MSI and EXE software deployment wizard across selected endpoints.π Push File: Multi-threaded administrative file and script distribution utility pushing files intoC$\Temp.π¬ Message: Multi-endpoint notification broadcaster supporting Modal Popups and Toast Banners.β‘ Power & WOL: Mass-dispatch Wake-on-LAN packets, remote screen lock, user logoff, reboot, or shutdown.
Live Status: Real-time reachability (π’ Online (Xms),π΄ Offline,π‘ Checking...,π΅ WinRM Only).Workstation State: Real-time presence telemetry (π’ Active,π€ Idle (1h 30m),π Locked (17h),πͺ Logged Off,π΄ Offline) with human-readable duration scaling.Computer Name: NetBIOS / DNS hostname with 1-click sorting.IPv4 Address: Active network adapter IP address.Logged-in User: Currently authenticated domain user (DOMAIN\User).Logon Time: Interactive session logon timestamp.Uptime: Real-time system uptime (β±οΈ 3d 12h,β±οΈ 18d 6h,β±οΈ 1mo 5d) with 1-click numerical duration sorting, color health thresholds, and last boot tooltip.Operating System: OS edition and build (Windows 10, 11, Server 2019/2022).Description: Active Directory computer description attribute.OU (Computer / User): Dual organizational unit placement for device and logged-in user.
Positioned directly beneath the DataGrid for rapid keyboard-first dispatching:
- Session Configuration Checkboxes:
View Only: Shadows the remote session without taking mouse or keyboard control.No Prompt: Uses/noConsentPromptwhen Group Policy permits unattended shadowing.Multi-Monitor: Spans across multi-monitor display setups (/multimon).Admin Console: Connects directly to the physical server console session (/admin), bypassing RDS CAL limitations.
- Primary Connection Buttons:
β‘ Connect Shadow Session(Enter): Hooks directly into RDS screen shadowing (mstsc.exe /shadow:<id> /control) for zero-lag mirroring without kicking the user off.π Quick Assist: Dedicated 1-click launcher for Microsoft Quick Assist featuring the official Microsoft Fluent Quick Assist icon embedded locally for 100% offline reliability.π₯οΈ Connect RDP Session(Ctrl+Enter): Launches standard Remote Desktop Protocol connection (mstsc.exe /v:<Host>).
- Line 1 (
π οΈ Tools):π» Console(Ctrl+T): Remote command terminal (CMD/PowerShell) with 1-click presets (whoami,gpupdate,sfc,ipconfig,ping).π» Specs(Ctrl+I): Visual hardware dashboard with gauges for CPU, RAM, Disk usage, BIOS, Serial/Tag, and continuous Uptime health tracker.π Task Mgr: Remote process controller displaying PID, Memory, and CPU time with instant search andπ End Process.βοΈ Services: Windows services manager with Start, Stop, Restart, Start Mode toggling, and 1-click Print Spooler restart.π¦ Software: Dual-engine software inventory with 1-click silent uninstallation for MSI and EXE packages.π Startup: Remote startup applications manager. Toggle programs Enabled/Disabled without deleting registry keys.π Events: Windows Event Log viewer with reverse-chronological streaming, severity badges, date range filters, and diagnostic presets.π¨οΈ Printers: Local and network printer manager. Add UNC shared printers, remove, inspect properties, pause/resume, set default, test print, and purge queues.π Live Perf: Sub-second live kernel performance monitor tracking CPU, RAM, Network RX/TX, and Disk I/O with historical sparklines and DIMM memory slot inspectors.π IP Config: Remote network hub. Switch DHCP β Static IP, flush DNS, register DNS, release/renew leases, and reset network adapters safely.π¬ Message(Ctrl+M): Remote user messaging dialog with exact character limits, Title/Subtitle/XL modes, Large Text toggle, and alert type badges.
- Line 2 (
π Folders & π€ Users):πΎ Open C$/: Opens\\<Host>\C$in Windows Explorer.π₯οΈ Desktop: Opens remote user's Desktop folder in Explorer.π₯ Downloads: Opens remote user's Downloads folder in Explorer.π Documents: Opens remote user's Documents folder in Explorer.ποΈ Net Drives(Ctrl+D): Remote mapped network drives manager (dual-engine inspection, add mapping with free letter auto-selection, edit, disconnect, test UNC, local open).π€ Profile Card(Ctrl+Shift+U): Enterprise 360Β° AD User Profile Inspector (40+ directory attributes, organizational hierarchy, contact info, security metrics, and interactive Group Membership Manager with Add/Remove group actions).π₯ Local Users: Local computer SAM accounts manager (provision users, reset passwords, enable/disable accounts).π Unlock User(Ctrl+U): Dynamic Active Directory account unlocker. Button turns red (β οΈ Account Locked) when account is locked.π Reset Pass(Ctrl+Shift+P): Remote password reset dialog with option to force password change at next logon.
- Single-Computer Selection Menu: Right-clicking a single machine presents a full administrative console organized into categorized flyout submenus:
π₯οΈ Screen Shadow & Remote Control βΈ: Connect Shadow Session, View Only, Remote Desktop, and Admin Console.βοΈ Administration & Management βΈ: View Profile Card, Edit Profile Attributes, Unlock Account, Reset Password, Local Users, Mapped Drives, Startup Apps, Edit Description, God Mode & Power Tweaks, Computer Management MMC, Task Scheduler MMC.π Diagnostics & Telemetry βΈ: System Specs, Live Performance Monitor, Task Manager, Windows Services, Software Inventory, Event Log Viewer, Printers & Queues, IP Config, Desktop Info HUD (BgInfo), Change Wallpaper, Ping Host.π οΈ Remote Maintenance & Automation βΈ: Deep Temp Clean, Inactivity & Idle Monitor Agent, Force GPUpdate, Deploy Software Package, Push File/Script, Open Browser URL, Open File/App, Send User Message, Flush DNS, Enable Remote Firewall Rules, Enable ICMP Echo Rule.β‘ Security, Clean & Power Options βΈ: Workstation Lock & Unlock Controller, Instant Screen Lock, Logoff User, Reboot, Shutdown, Wake-on-LAN.
- Multi-Computer Bulk Selection Menu: Right-clicking multiple selected machines automatically filters out single-host tools, presenting a focused list of 17 bulk-supported operations.
Windows_AD_Remote_Administration_Control_Center/
βββ Windows AD-Admin Control Center v2.6.5.exe # Standalone portable Windows executable (~600 KB)
βββ Configure_Endpoint_GPO.ps1 # Automated endpoint GPO & firewall configuration script
βββ Run_AD_Remote_Control.bat # 1-Click launcher script (auto-launches versioned exe)
βββ CHECKSUMS.txt # Official SHA-256 integrity checksums
βββ README.md # Complete project documentation & quick start
βββ USAGE_GUIDE.md # In-depth operator reference manual & GPO guide
βββ USAGE_GUIDE.txt # Plain text version for in-app fallback viewer
βββ CHANGELOG.md # Detailed version release notes & history
βββ LICENSE # MIT License
Download the latest Windows AD-Admin Control Center v2.6.5.exe from GitHub Releases.
Right-click Windows AD-Admin Control Center v2.6.5.exe and select Run as Administrator (using Domain Admin credentials):
"Windows AD-Admin Control Center v2.6.5.exe"Alternatively, run the included launcher script:
Run_AD_Remote_Control.batImportant
Strict Domain / Enterprise Administrative Authorization Enforcement:
To safeguard domain environments and prevent unauthorized workstation management, the application verifies the security identity of the launching user at startup. The application will ONLY launch if the user belongs to at least one of the following Domain / Enterprise administrative accounts:
- Domain Admins (Well-Known SID ending in
-512) - Enterprise Admins (Well-Known SID ending in
-519) - Schema Admins (Well-Known SID ending in
-518) - Account Operators (Well-Known SID ending in
-548) - Server Operators (Well-Known SID ending in
-549) - Authorized Active Directory Administrative Groups (e.g.,
IT-Admins,IT Admins,IT Administrators,Server Admins,System Admins,Security Admins,Network Admins,Cloud Admins).
BUILTIN\Administrators / Local Administrators) are blocked from executing this suite to maintain enterprise governance.
π‘ Need custom groups added or removed? If your organization uses specialized administrative group names or specific role requirements, please request a feature or open an issue on GitHub or reach out via Telegram, and the author will gladly make the changes for your environment!
- Domain Admins: Fully privileged across all domain endpoints, Active Directory user objects, and admin shares out of the box.
- Delegated Helpdesk Technicians: Ensure support staff are members of an authorized domain administrative group (e.g.
Domain AdminsorIT-Admins) with delegated Active Directory permissions on target user OUs indsa.mscfor password resets and account unlocking.
To enable shadowing without disconnecting active users:
- Open
gpmc.mscon your Domain Controller and edit your Workstations Policy. - Navigate to:
Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Connections - Configure:
- Set rules for remote control of Remote Desktop Services user sessions:
- Set to Enabled.
- Choose Full Control without user's permission (for instant unattended screen mirror) or Full Control with user's permission (prompts user to allow/deny).
- Allow users to connect remotely by using Remote Desktop Services:
- Set to Enabled.
- Set rules for remote control of Remote Desktop Services user sessions:
- Run
gpupdate /forceon client workstations.
Ensure the following ports and predefined rule groups are enabled via GPO:
- TCP 3389: Remote Desktop & Remote Shadowing
- TCP 445 & 139: SMB File Sharing (
C$access, remote folder navigation, deep temp clean) - TCP 135 & Dynamic RPC: WMI Management (Hardware Specs, Task Manager, Services, Remote Console, Drive Mapping)
- TCP 5985: WinRM HTTP (for Action Center Toast notifications)
- ICMPv4: Ping echo request for live online/offline latency detection
- Remote Registry Service: Startup type set to Automatic for instant cross-profile software and drive mapping scans.
When you publish a new version on GitHub Releases:
- Users click
π Updatesin the application header (or the app notifies them automatically). - The changelog and release notes appear inside the app.
- Clicking
β‘ Update & Restart Nowdownloads the new.exeand updates the app in-place in ~1.5 seconds. - No browser redirection, no manual file copying, no installers!
| Shortcut | Action |
|---|---|
Ctrl + S / Ctrl + F |
Focus Quick Search box and select all text |
F5 / Ctrl + R |
Refresh computer inventory from Active Directory |
Enter |
Connect Shadow Session (screen mirror) to selected computer |
Ctrl + Enter |
Connect Remote Desktop (RDP) login |
Ctrl + Win + Q |
Launch Microsoft Quick Assist (or click the dedicated Quick Assist button) |
Ctrl + P |
Ping selected computer and display latency |
Ctrl + T |
Open interactive in-app Remote Console (CMD / PowerShell) |
Ctrl + I |
Open System Hardware Diagnostics & Specs |
Ctrl + D |
Open Remote Mapped Network Drives Manager (Add / Edit / Remove) |
Ctrl + M |
Open Send User Notification Message dialog |
Ctrl + U |
Unlock logged-in user account in Active Directory |
Ctrl + Shift + P |
Reset domain user password |
Ctrl + Shift + U |
Open 360Β° Active Directory User Profile Inspector |
ESC |
Clear search text (when focused), or close any open popup modal |
If this application saves you and your IT team hours of tedious administrative work:
- β Star the Repository: Drop a star on GitHub to help other sysadmins discover this free tool!
- π¬ Join the Discussion: Share workflow feedback, request custom administrative group authorizations, or submit feature requests on GitHub Discussions and Telegram.
- π’ Share with Fellow Sysadmins: Mention it on Reddit (
r/sysadmin,r/PowerShell), LinkedIn, or your internal IT engineering channels.
Developed with β€οΈ by Askarali Mattummal (LinkedIn Profile | GitHub | Telegram Community).
Licensed under the MIT License & Distribution Terms.
Caution
Authorized IT Administrative Use Only: This software is designed, developed, and published strictly for authorized IT systems administrators and certified support personnel to maintain, monitor, and troubleshoot authorized enterprise domain infrastructure. Any unauthorized deployment, surveillance, privacy violation, or malicious use is strictly prohibited. The author assumes no responsibility or liability for damages or legal consequences arising from misuse. Please consult the LICENSE for complete terms of use and liability disclaimers.
