Active Directory Ports: Service And Network Port Requirements For ...
Maybe your like

Active Directory communication involves the following ports and as a system administrator, you must be familiar with some of the following ports already. In this article, we will discuss the Service and Network Port requirements for Active Directory. You may want to see the following related guides: Pass-Through Authentication with on-Premise AD, reasons to deploy AAD, Microsoft Azure Active Directory: How to setup Azure AD Tenant, and how to set up an Azure AD Tenant, and how to add a custom domain in the Azure Active directory.
Enterprises use Active Directory for authentication, server and workstation management, group policy management, etc. In this guide, the most important network ports, protocols, and services used by Microsoft client and server operating systems. And their subcomponents are listed in the table below.
If you enable the Windows Firewall or if there is an external Firewall for your Active Directory Domain Services (ADDS) in this case Domain Controller Server. You need to set up the allowed port for Domain Controller correctly. The table below will show you all ports that are needed for the domain controller.
Network Port Security for Microsoft Server Products
Microsoft server products use a variety of network ports and protocols to communicate with client systems and with other server systems over the network.
You need dedicated firewalls, host-based firewalls, and IPSec filters to secure your network. If you configure these technologies to block ports and protocols a specific server uses, it won’t respond to client requests.
| Application protocol | Protocol | Ports |
|---|---|---|
| Active Directory Web Services (ADWS) | TCP | 9389 |
| Active Directory Management Gateway Service | TCP | 9389 |
| Global Catalog | TCP | 3269 |
| Global Catalog | TCP | 3268 |
| ICMP | No port number | |
| Lightweight Directory Access Protocol (LDAP) Server | TCP | 389 |
| LDAP Server | UDP | 389 |
| LDAP SSL | TCP | 636 |
| IPsec ISAKMP | UDP | 500 |
| NAT-T | UDP | 4500 |
| RPC | TCP | 135 |
| RPC randomly allocated high TCP ports¹ | TCP | 1024 – 500049152 – 65535² |
| SMB | TCP | 445 |
The LSASS process runs Active Directory. This requires specific port connections between domain controllers and client servers on TCP ports 1024 to 65535. You may want to learn more here.
I hope you found this blog post on the “Service and Network Port requirements for Active Directory” helpful. Please let me know in the comment session if you have any questions.
Rate this postThank you for reading this post. Kindly share it with others.
- X
- Tumblr
- Telegram
- Mastodon
- Bluesky
- Threads
- Nextdoor
Tag » Ad Dc Ports
-
More Information
-
Ports To Be Opened For AD / DC - TechNet - Microsoft
-
Complete List Of Active Directory Ports And What They Do Explained
-
Cyber Security Awareness Month - Day 27 - Active Directory Ports
-
Firewall Ports Required To Join AD Domain - AventisTech
-
Active Directory Firewall Ports – Let's Try To Make This Simple
-
A Guide To Active Directory Ports And Authentication Protocols
-
Ports Required To Talk To Windows DC For AD Authentication
-
Domain Controllers Required Ports: Use PowerShell To Check If They ...
-
What Firewall Ports For Active Directory?
-
Firewall Ports To Open For Active Directory Communication
-
Change The Default Port For The Active Directory Server
-
Samba AD DC Port Usage - SambaWiki
-
Firewall Ports For AD Domain Join - Devopstales