What are the requirements for running an Active Directory scan?
This article describes the target, credentials, scan profile settings, and network ports required to run an Active Directory scan.
Before you start
Make sure to configure a scan profile for authenticated scanning.
Target
Point the scan at a single Domain Controller, by IP address or FQDN. The scan is not a subnet sweep. One Domain Controller acts as the entry point for all LDAP queries, SYSVOL access, and per-Domain Controller network probes.
Use the PDC Emulator where possible
The PDC Emulator holds the authoritative copy of password policy, time sync, and account lockout state. Scanning a secondary Domain Controller is supported, but it may return slightly stale data for recently changed objects.
Identify the PDC Emulator with either of these commands:
(Get-ADDomain).PDCEmulator
nltest /dcname:<domain>
One scan per domain
A single scan against one Domain Controller covers the entire domain. For multi-domain forests, run one scan per domain. Cross-domain data is discovered automatically, but each domain's rules are evaluated independently.
Credentials
The scanner authenticates over SMB and LDAP using NTLM. Use one of the following accounts:
- Option 1: A standard domain user with remote registry read access on the Domain Controllers.
- Option 2: A member of Domain Admins (full coverage).
A standard domain user without remote registry read access does not work. Because the scanner uses NTLM, the account must not be a member of Protected Users. LocalAccountTokenFilterPolicy is not needed, as it only affects local accounts, not domain accounts.
| Field: | Value: |
|---|---|
| Domain | FQDN of the domain (e.g., corp.example.com). The NetBIOS name is not supported. |
| Username | SAM account name only (e.g., svc-scanner). |
| Password | Account password. |
| NTLM | Default NTLMv2 and NTLMv1, or NTLMv2 only if the domain disables NTLMv1. |
Option 1: Standard domain user
- Create an account that is a member of Domain Users only.
- Make sure the Remote Registry service is running on the Domain Controllers.
- In a GPO linked to the Domain Controllers OU, go to Security Options > Network access: Remotely accessible registry paths and sub-paths, and add these paths:
- System\CurrentControlSet\Services\NTDS
- System\CurrentControlSet\Services\WebClient
- System\CurrentControlSet\Control\SecurityProviders\SCHANNEL
- Run gpupdate /force on the Domain Controllers.
The GPO replaces the whole list
Also enter the existing entries, which you can list on a Domain Controller with (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths').Machine. The added paths become readable by all domain users, not only the scan account.
The following are not covered with Option 1:
- Fine-grained password policies (PSOs), unless Read is delegated to the account on the PSO objects in CN=Password Settings Container,CN=System,<domain DN>.
- LDAP signing and channel binding registry values. The scanner tests these over the network instead.
- Active Directory objects that don't grant Read to Authenticated Users, for example restricted certificate templates.
If Authenticated Users is not a member of Pre-Windows 2000 Compatible Access, many account, delegation, and DNS zone checks are incomplete. In that case, use Option 2.
Option 2: Domain Admin
No extra configuration is needed beyond the Remote Registry service.
Remote Registry access required
The scanner reads the remote registry on the target host to confirm that it is a Domain Controller before running Active Directory-specific checks. If the Remote Registry service is not running on the target Domain Controller, the scanner cannot verify the Domain Controller role and the scan will not return results.
Read more about systems and requirements:
What are the supported systems and requirements?
Read rights
Checks that read security descriptors on privileged objects, AdminSDHolder ACLs, or RODC password replication groups may return incomplete data if the account lacks the corresponding read rights.
The authentication record can be reused across scan profiles. Saved credentials are encrypted at rest.
Scan profile
The Active Directory scan is driven by a small, fixed set of plugins. Two profile presets are available. Both can be customized under Edit network vulnerability scan profile > Vulnerabilities.
- AD Scan — Standard: Built on the Basic Network Scan profile, plus the entire Active Directory script family and these plugins:
| HID: | Plugin: |
|---|---|
| HID-2-1-13479 | SMB Authorization |
| HID-2-1-33740 | SMB Login |
| HID-2-1-5320777 | Active Directory Healthcheck Collector |
- AD Scan — Extended: Built on the Standard Network Scan profile, with the same plugins and script family. Use this when you also need broader host-level coverage of the target Domain Controller in the same scan.
To configure a custom profile, go to Vulnerabilities and add:
- Include > Category: Active Directory.
- Include > Vulnerability: [HID-2-1-044560] Host Summary.
- Include > Vulnerability: [HID-2-1-5320777] Active Directory Healthcheck Collector.
Show low probability vulnerabilities
Enabling Show low probability vulnerabilities in scan result is recommended for AD scans. Several baseline checks are deliberately scored as low-probability and will not appear in the report otherwise.
Authentication record
Configure the authentication record under the Authentication tab:
| Field: | Value: |
|---|---|
| Domain | Domain FQDN (e.g., corp.example.com), not the NetBIOS name. |
| Username | SAM account name only (e.g., svc-scanner). |
| Password | Account password. |
| NTLM mode | Use NTLMv2 and NTLMv1 (default) is appropriate for most domains. Select Use NTLMv2 only when NTLMv1 has been disabled. |
Network ports
The Scanner Appliance requires direct network access from the scan node to the target Domain Controller.
| Port: | Protocol: | Used for: |
|---|---|---|
| 389 | TCP | LDAP — primary directory queries. |
| 636 | TCP | LDAPS — preferred when available. |
| 445 | TCP | SMB — SYSVOL access, null-session probe, SMB signing/version checks. |
| 135 | TCP | RPC endpoint mapper — DCE/RPC interface probing. |
| 53 | UDP/TCP | DNS — DC resolution and per-DC DNS registration check. |
| 80 | TCP | HTTP — WebClient / WebDAV service detection (optional). |
| 3268 | TCP | Global Catalog LDAP (optional, used if available). |
| 3269 | TCP | Global Catalog LDAPS (optional). |
Minimum required ports
Ports 389 (or 636) and 445 are the minimum required. Phases that depend on unreachable ports are skipped; the scan completes with the data available.
When port 636 is reachable, LDAPS is selected automatically. LDAPS is strongly recommended as it encrypts directory queries and credentials in transit.