Skip to main content
Version: 2.2.1-preview

AD-DCD-01 - DC non-standard LDAP port count should be retrievable

Overviewโ€‹

Domain controllers typically use the standard LDAP port (389) for directory services communication. Non-standard LDAP ports may indicate:

  • Custom configurations that could affect compatibility with standard LDAP clients and tools
  • Security evasion attempts where alternate ports are used to bypass network monitoring
  • Legacy configurations that haven't been updated to standard settings
  • Multi-tenant or specialized deployments with unique port requirements

While non-standard ports may be intentional for specific scenarios, they can cause issues with:

  • LDAP client connectivity
  • Directory synchronization services
  • Authentication protocols expecting standard ports
  • Network security monitoring and firewall rules

Security Recommendationโ€‹

  1. Document intentional deviations: If non-standard ports are required, ensure they are well-documented with business justification
  2. Review firewall rules: Ensure proper firewall rules are in place for any non-standard ports
  3. Monitor for unauthorized changes: Non-standard ports without documentation may indicate unauthorized configuration changes
  4. Consider standardization: Where possible, use standard ports to simplify management and troubleshooting

How the Test Worksโ€‹

This test retrieves all domain controllers and checks their configured LDAP port. The standard LDAP port is 389. The test reports:

  • Total number of domain controllers
  • Number of DCs using the standard LDAP port (389)
  • Number of DCs using non-standard LDAP ports
  • Names of DCs with non-standard ports and the specific ports they use
  • Test-MtAdDcNonStandardLdapsPortCount - Checks for non-standard secure LDAP ports
  • Test-MtAdDcSiteCoverageCount - Analyzes DC distribution across sites

Test Metadataโ€‹

FieldValue
Test IDAD-DCD-01
SeverityInfo
SuiteActive Directory
CategoryAD.DomainController
PowerShell testTest-MtAdDcNonStandardLdapPortCount
TagsAD, AD-DCD-01, AD.DomainController

Sourceโ€‹

  • Pester test: tests/ad/domaincontroller/Test-MtAdDcNonStandardLdapPortCount.Tests.ps1
  • PowerShell source: powershell/public/ad/domaincontroller/Test-MtAdDcNonStandardLdapPortCount.ps1