AD-DCD-02 - DC non-standard LDAPS port count should be retrievable
Overviewβ
Domain controllers typically use the standard LDAPS port (636) for secure directory services communication. Non-standard LDAPS ports may indicate:
- Custom SSL/TLS configurations that could affect secure LDAP client connectivity
- Security evasion attempts where alternate ports are used to bypass network monitoring
- Legacy or specialized deployments with unique security requirements
- Load balancer or proxy configurations using different port mappings
Using non-standard LDAPS ports can cause issues with:
- Secure LDAP (LDAPS) client connectivity
- Certificate-based authentication
- Applications hardcoded to use port 636
- Network security monitoring and compliance auditing
Security Recommendationβ
- Use standard ports where possible: Port 636 is the industry standard for LDAPS and should be used unless there's a specific requirement
- Document security exceptions: Any non-standard ports should be documented with security justification
- Ensure proper certificate configuration: Non-standard LDAPS ports must have valid SSL/TLS certificates configured
- Audit regularly: Review non-standard port usage during security audits to detect unauthorized changes
How the Test Worksβ
This test retrieves all domain controllers and checks their configured LDAPS (SSL) port. The standard LDAPS port is 636. The test reports:
- Total number of domain controllers
- Number of DCs using the standard LDAPS port (636)
- Number of DCs using non-standard LDAPS ports
- Names of DCs with non-standard ports and the specific ports they use
Related Testsβ
Test-MtAdDcNonStandardLdapPortCount- Checks for non-standard LDAP portsTest-MtAdDcReadOnlyCount- Analyzes RODC deployment
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DCD-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DomainController |
| PowerShell test | Test-MtAdDcNonStandardLdapsPortCount |
| Tags | AD, AD-DCD-02, AD.DomainController |
Sourceβ
- Pester test:
tests/ad/domaincontroller/Test-MtAdDcNonStandardLdapsPortCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domaincontroller/Test-MtAdDcNonStandardLdapsPortCount.ps1

