• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 406
  • Last Modified:

Application needs to lookup Active Directory info


We are running AD 2003. We have multiple domains within the same forest - emea.kam.com and apac.kam.com, forest root kam.com

We have an application that will need to query AD to lookup attributes of users, their group membership and other info.

What port does the app need to query the DC on - 386 (LDAP) or 3268 (GC)?
  • 2
2 Solutions
Mike KlineCommented:
It depends on what type of groups and what the other info is.  Look at the last section here   http://technet.microsoft.com/en-us/library/cc978012.aspx

The GC only holds a partial set of attributes so while a GC in emea knows about every object it doesn't contain every attribute for every object.


Could you reveal the name of application,you are going to use in AD for performing ldap query.

The general attribute can be queried by most of the application using GC but if you want specific attribute, you require some set of programming/scripting to achieve that.


You will surely require 389 for ldap server & for secure 636(LDAP SSL)

Same for GC 3268 & 3269 for SSL.

It might require 53 for DNS server lookup.

Check the below article its for windows 2000 but you will get an idea.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now