AD-DCD-01 - DC non-standard LDAP port count should be retrievable
Overviewโ
Domain controllers typically use the standard LDAP port (389) for directory services communication. Non-standard LDAP ports may indicate:
- Custom configurations that could affect compatibility with standard LDAP clients and tools
- Security evasion attempts where alternate ports are used to bypass network monitoring
- Legacy configurations that haven't been updated to standard settings
- Multi-tenant or specialized deployments with unique port requirements
While non-standard ports may be intentional for specific scenarios, they can cause issues with:
- LDAP client connectivity
- Directory synchronization services
- Authentication protocols expecting standard ports
- Network security monitoring and firewall rules
Security Recommendationโ
- Document intentional deviations: If non-standard ports are required, ensure they are well-documented with business justification
- Review firewall rules: Ensure proper firewall rules are in place for any non-standard ports
- Monitor for unauthorized changes: Non-standard ports without documentation may indicate unauthorized configuration changes
- Consider standardization: Where possible, use standard ports to simplify management and troubleshooting
How the Test Worksโ
This test retrieves all domain controllers and checks their configured LDAP port. The standard LDAP port is 389. The test reports:
- Total number of domain controllers
- Number of DCs using the standard LDAP port (389)
- Number of DCs using non-standard LDAP ports
- Names of DCs with non-standard ports and the specific ports they use
Related Testsโ
Test-MtAdDcNonStandardLdapsPortCount- Checks for non-standard secure LDAP portsTest-MtAdDcSiteCoverageCount- Analyzes DC distribution across sites
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DCD-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DomainController |
| PowerShell test | Test-MtAdDcNonStandardLdapPortCount |
| Tags | AD, AD-DCD-01, AD.DomainController |
Sourceโ
- Pester test:
tests/ad/domaincontroller/Test-MtAdDcNonStandardLdapPortCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domaincontroller/Test-MtAdDcNonStandardLdapPortCount.ps1

