Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To join a Windows 11 PC to an on-premises Active Directory domain, confirm the PC is running an eligible Windows edition, connect it to the organization’s network and DNS, then use Settings > Accounts > Access work or school > Connect > Join this device to a local Active Directory domain. You’ll also need local administrator rights and domain credentials authorized for the join. First confirm with IT that this is the required path: joining an Active Directory domain is different from joining Microsoft Entra ID.
Confirm which directory your organization uses
A local Active Directory domain join connects the PC to an organization’s on-premises Active Directory Domain Services (AD DS) environment. Microsoft Entra ID is a separate cloud identity and device-join path; the two options are not interchangeable. Ask your IT administrator which directory and enrollment process applies to the device. Microsoft documents the separate Windows connection paths in its Windows device enrollment guidance.
| Path | When it applies | What to do |
|---|---|---|
| On-premises Active Directory | The organization uses an AD DS domain and has directed you to join the PC to it. | Use the local Active Directory domain option in Settings and the domain name and credentials supplied by IT. |
| Microsoft Entra ID | The organization uses its cloud identity environment or has specifically directed you to use its Entra join or enrollment process. | Follow the organization’s Entra instructions rather than choosing the local Active Directory option. |
Check requirements before joining
- Eligible Windows edition: Microsoft lists Windows 11 Pro, Enterprise, and specified Pro variants as eligible client editions for domain joining. Check the PC’s edition before troubleshooting a failed attempt. The edition alone does not provide network access, credentials, or domain permissions. See Microsoft’s domain-join requirements.
- Organization network and DNS: The PC must be able to reach domain services, and its DNS configuration must resolve the domain and domain controllers. If you are off-site, ask IT whether you need to connect to the organization’s network or VPN before joining.
- Authorized credentials and rights: You need local administrator rights on the PC. The identity used for the join must also have the necessary domain permissions. Those permissions depend on whether the computer account will be created during the join or already exists in Active Directory.
- Correct domain name: Get the DNS domain name from IT. Do not guess it from an email address or use credentials that have not been approved for this task.
IT may prepare a computer account in advance, sometimes called prestaging. Microsoft describes this as optional; it can let an administrator place the account in an organizational unit and prepare its permissions before the PC joins. If an account has already been created, ask IT to confirm that it is intended for this device and that your joining identity is authorized to use it. See Microsoft’s guidance on computer-account permissions and domain joining.
Join the PC in Windows 11 Settings
- Connect the PC to the organization’s network or the approved VPN, if IT requires one for domain access.
- Open Start > Settings > Accounts > Access work or school.
- Select Connect, then choose Join this device to a local Active Directory domain. Do not select a work-account or Entra option unless IT has instructed you to use that path.
- Enter the domain name provided by IT and select Next.
- When prompted, enter the authorized domain credentials. Review and accept the confirmation if shown.
- Restart when Windows requests it. After restart, sign in with the organization’s domain account if IT has told you to do so.
A successful join adds the device to the domain; it does not by itself guarantee that a particular user account, application, policy, or resource will be available. Those depend on the organization’s configuration. If the expected sign-in or access does not work, ask IT to verify the device’s membership and account setup.
#1 Best Overall
Administrator alternatives
For managed deployments or administrator-led work, Microsoft also documents joining from an elevated Command Prompt with netdom join and from elevated PowerShell with Add-Computer -DomainName "YourDomainName" -Credential (Get-Credential), followed by a restart. These methods require the correct domain name and an identity with the appropriate rights; they are not shortcuts around the same network and permission requirements. Follow your organization’s deployment procedure rather than substituting guessed values. Microsoft’s instructions are in its domain-join documentation.
Troubleshoot a failed domain join
Record the exact error message before trying again. Microsoft’s domain-join troubleshooting guidance identifies DNS as central to Active Directory operation: “DNS is the heart of Active Directory (AD) and makes things work correctly, including domain join.” Check the likely cause that matches the error:
Rank #2
Windows cannot find the domain or no credential prompt appears
- Confirm the PC is on the required organization network or VPN.
- Ask IT to check that the PC is using the organization’s correct DNS servers and search suffixes.
- Confirm that the domain name and domain controllers resolve from the PC. A general internet connection does not establish that the PC can find internal domain services.
Credentials or permissions are rejected
- Verify the account name and password with IT, especially if the account is permitted to join devices but is not your everyday sign-in account.
- Ask whether the computer account is being created during the join or was prestaged. The required rights differ by scenario, including when an existing computer account is reused.
- Do not reset, delete, or take ownership of an existing computer account without authorization. IT can check whether it belongs to this device and whether the joining identity has the required rights.
Microsoft discusses these differences in its domain-join authentication troubleshooting guidance.
A network or RPC-style error appears
Check that the PC can reach domain controllers on the organization’s network. A VPN, firewall, or other network device may prevent required communication even when ordinary web browsing works. Ask IT to investigate network access and filtering; do not change firewall or domain policy settings based on a generic port list.
Rank #3
Find more detail in the join log
For further diagnosis, preserve the error and inspect C:WindowsDebugnetsetup.log. Microsoft identifies this file as a useful record of domain-join activity. Share the relevant error and log details with IT so they can check the domain controller, DNS, credentials, and computer-account state together.
Quick Recap
Rank #4
- Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
- ABIS BOOK
- Packt Publishing
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

