What firewall ports to use DSA.msc from a trusted domain?

n4 41 Reputation points
2023-02-09T19:21:57.57+00:00

Domain A trusts domain B.

I want to open DSA.msc in domain B and use it to manage Domain A.

I can do this from the domain controllers, but not anywhere else - and I need to make this available from a jump server/PAW.

Is it ALL the domain trust port list that needs opened? Or is there a shorter list for using DSA?

I'm afraid its ALL - but need to confirm.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2023-02-09T19:27:42.2833333+00:00

    You'll find the list here. You can trial and error some subset to see if things can work out for you.

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts#windows-server-2008-and-later-versions

     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. n4 41 Reputation points
    2023-02-09T21:00:12.4233333+00:00

    All or almost all of the ports in the AD Trust list are needed. If I get a chance to ask my network team what the exact results were I will post back. They used a firewall feature to detect the port usage. Fancy.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.