What firewall ports to use DSA.msc from a trusted domain?

n4 41 Reputation points
2023-02-09T19:21:57.57+00:00

Domain A trusts domain B.

I want to open DSA.msc in domain B and use it to manage Domain A.

I can do this from the domain controllers, but not anywhere else - and I need to make this available from a jump server/PAW.

Is it ALL the domain trust port list that needs opened? Or is there a shorter list for using DSA?

I'm afraid its ALL - but need to confirm.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,915 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,685 questions
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2023-02-09T19:27:42.2833333+00:00

    You'll find the list here. You can trial and error some subset to see if things can work out for you.

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts#windows-server-2008-and-later-versions

     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. n4 41 Reputation points
    2023-02-09T21:00:12.4233333+00:00

    All or almost all of the ports in the AD Trust list are needed. If I get a chance to ask my network team what the exact results were I will post back. They used a firewall feature to detect the port usage. Fancy.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.