Need to know which ports to open in firewall for changing ad users passwords .

shihas shamsudheen 26 Reputation points
2021-04-01T06:49:05.847+00:00

Dear Team,

In our organization users can change their ad passwords by clicking alt+cntl+delete when they are in LAN. when users are connected to the vpn , they cant change the ad passwords. Because the port is not opened in firewall.

Please advise as which port should be open in firewall for ad password changing purpose

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
{count} votes

2 answers

Sort by: Most helpful
  1. SUNOJ KUMAR YELURU 15,496 Reputation points MVP
    2021-04-01T09:09:15.523+00:00

    Hi @shihasshamsudheen-6893
    Thank You for posting in Q & A.

    UDP 389, UDP/TCP 88, and UDP/TCP 464 (password change requests) ports are open for the domain controllers in the user domain.
    refer - https://learn.microsoft.com/en-us/archive/blogs/activedirectoryua/conditions-for-kerberos-to-be-used-over-an-external-trust

    If the Answer is helpful, please click Accept Answer and up-vote, this can be beneficial to other community members.

    0 comments No comments

  2. Anonymous
    2021-04-01T12:20:24.54+00:00
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.