Log in

Enter your email and we'll send you a one-time login code.

Enter your code

We sent a 6-digit code to your email.

Runs entirely on your network — no cloud, no telemetry

Active Directory administration, without leaving your domain.

Everything you'd reach for in Active Directory Users and Computers — plus LAPS, bulk operations, and audit logging — in one signed, offline-activated desktop tool. Built for IT teams who need real AD work done fast, and nothing phoning home while they do it.

Prefer a direct download (e.g. Microsoft Store blocked on your network)? Get the .zip here → (extract the folder, then run QuietAD.exe from inside it)
1license, unlimited machines
0cloud dependencies
Ed25519signed activation
Select Destination OU
CONTOSO.COM
OU=Corporate Workstations
OU=Finance-WKS42 objects
OU=Engineering-WKS118 objects
OU=Corporate Users
OU=ActiveUsersverified
// what it does

Everything a helpdesk-to-sysadmin team touches in AD, in one window.

Not a script collection. A single tool with the guardrails your directory actually needs — scoped moves, audit logging, and confirmation on anything destructive.

Users & groups

Add/remove from groups, unlock, enable/disable, move between OUs — searchable pickers instead of hand-typed DNs.

Computers & LAPS

Move, enable, disable, delete workstations, and retrieve LAPS passwords — legacy and modern Windows LAPS both supported.

Bulk operations

Paste, import CSV, or multi-select from a picker — move or delete a batch of computers with one confirmed action and a results log.

Scoped by design

Restrict which OUs are even reachable for moves and enable/disable — so a helpdesk build can't wander into Domain Admins.

Every action logged

Who, what, when, and the result — written to a shared log, with automatic local fallback if the network drops.

Activate once, done

One signed license file per organization. No seat counting, no per-machine limits, no license server to keep alive.

Built for the phone queue

Search by username, email, name, or employee ID — see a caller's full status before touching anything: locked, disabled, group memberships, last logon, OU. Same lookup exists for computers too: OS, version, last logon, status.

Onboard a new hire in one form

Name, username, initial password, destination OU — creates the account, sets the password over an encrypted connection, and forces a change at next logon. No ADUC, no PowerShell.

Groups, without the guesswork

Look up any group and see its full member list, export it to CSV for an audit or a ticket, or paste a list of usernames and bulk add or remove them from a group in one confirmed action — no more one-at-a-time membership changes.

// the actual interface

Real screenshots. Nothing dressed up for the website.

Three tabs, one window — user & group operations, computer & LAPS operations, and bulk actions. Click a tab below the same way you would in the app.

User & Group
Computer
Helpdesk
Settings
Active Directory Manager — User & Group tab showing group membership, account operations, and the new Group Lookup and Bulk Group Membership tools Active Directory Manager — Computer tab showing move, delete, enable/disable, LAPS retrieval, and bulk operations Active Directory Manager — Helpdesk tab showing User Lookup, Computer Lookup, locked-out accounts, and new user creation Active Directory Manager — Settings tab showing admin-configurable OU restrictions and Favorite OUs

User & Group tab — group membership, account unlock/enable/disable, and moving users between OUs.

// why it's safe to run

Nothing leaves your domain that isn't supposed to.

This is a desktop tool that talks to your domain controller and nothing else. There's no vendor server in the loop for it to work.

Fully offline activation

A signed .lic file, verified locally against an embedded public key. No license server, no internet requirement to run.

Encrypted local credentials

Saved admin credentials are Fernet-encrypted on disk — never stored or transmitted in plaintext.

Confidential attributes over LDAPS

Password resets and LAPS retrieval use an encrypted channel, matching what AD itself requires for confidential attributes.

Idle session timeout

Saved passwords clear automatically after inactivity, forcing re-authentication before any further changes.

No permissions granted or bypassed

QuietAD doesn't run as a privileged service account of its own — it uses whatever AD account you connect it with, and every action is still checked by AD's own delegation model. An account without rights on an OU gets rejected by AD itself, exactly as it would in ADUC or PowerShell.

// documentation

A real manual, not just a FAQ page.

Every tab, every field, every setting — covered in one PDF.

QuietAD User Guide

Installation, activation, every tab and field explained, the full security model, and a troubleshooting table — for admins evaluating QuietAD and customers already running it.

Download User Guide (PDF)
// pricing

Try it, or just get the real thing.

No per-seat counting. No subscription to babysit.

14-Day Trial

$25 / 14 days

Full functionality, same signed activation, just a 14-day license instead of perpetual.

cards
Powered by paypal

At checkout, add your organization name in PayPal's "special instructions to seller" note, and use an email you check — that's where your signed .lic file will be sent. If you forget, email support@quietad.online with your organization name after paying.

Get QuietAD from the Microsoft Store → (or download the .zip directly) — the app just needs your license file to activate once it arrives.

All sales are final. Refund Policy

Perpetual license
$799 one-time

Priced per organization, not per machine or per admin.

  • Unlimited machines within your organization
  • Own it outright — no recurring fee
  • Legacy & modern Windows LAPS support
  • Offline activation, no ongoing internet requirement
  • Free updates within your major version
Log in to purchase a license.