Skip to main content

AD FS Ports

Review a full list of protocols and ports required for monitoring logon activities performed using Active Directory Federation Services (AD FS).

  • Allow outbound connections from the dynamic (1024 - 65535) local port on the computer where Netwrix Auditor Server resides.
  • Allow outbound connections to remote ports on the source and inbound connections to local ports on the target.

Tip for reading the table: For example, on the computer where Netwrix Auditor Server resides (source), allow outbound connections to remote 389 TCP port. On domain controllers in your domain (target), allow inbound connections to local 389 TCP port.

PortProtocolSourceTargetPurpose
389TCPNetwrix Auditor ServerDomain controllersLDAP DC query Account resolve
53TCPNetwrix Auditor ServerDNS ServerDNS Client
135 + Dynamic: 1024 -65535TCPNetwrix Auditor ServerDomain controllersWindows Management Instrumentation Firewall configuration
135TCPNetwrix Auditor ServerDomain controllersService Control Manager Remote Protocol (RPC) Core Service installation
137 through 139UDPNetwrix Auditor ServerDomain controllersService Control Manager Remote Protocol (RPC) Core Service installation
445TCPNetwrix Auditor ServerDomain controllersSMB 2.0/3.0
5985 (for HTTP) 5986 (for HTTPS)TCPNetwrix Auditor ServerAD FS serversWindows Remote Management (WinRM)