We have a lot of errors, when we upgraded to Windows Server 2025 Domain Controllers

Екатерина Куклева 20 Баллы репутации
2025-12-05T13:31:48.8033333+00:00

Good day,

version was previously installed on DC Windows Server 2022

In a test environment we've deployed Windows Server 2025 Domain Controllers

After that we have a lot of errors in event logs.

eventid 3079 - the directory blocked access to one or more confidential attributes on one or more ldap. We don't know about impact... how critical are they?

They come from users and computers, approximately once an hour.

There are no such errors on domain controllers of the previous version.

Could you please advise,

When we deploy a new version of a domain controller, does this mean that services or applications will stop working, is this related to Kerberos or new protocol versions?

Thank you so much


Moderator edited tags from Community Center | News & Announcements to Windows Server. Selecting the right tags can help your question reach the right community members and get answers faster.

Windows для бизнеса | Windows Server | Службы каталогов | Active Directory
Комментариев: 0 Без комментариев

Ответ, принятый автором вопроса
Kate Pham (WICLOUD CORPORATION) 825 Баллы репутации Внешний персонал Microsoft Модератор
2025-12-09T02:43:36.8533333+00:00

Hi sir.

You might encounter unexpected results for operations on confidential attributes on Windows Server 2025 DCs. Allow me to explain new requirements for using LDAP clients to access confidential attributes while they're connected to Windows Server 2025-based domain controllers (DCs).

When you search for or edit Active Directory Domain Services (AD DS) objects, you notice the following behavior:

  • When you run a Lightweight Directory Access Protocol (LDAP) search request against a Windows Server 2025-based DC, the resulting attribute list doesn't include confidential attributes. However, if you run the same LDAP query against a DC that runs on Windows Server 2022 or earlier, you obtain a full attribute list in the response.

Cause:

Because of new functionality in Windows Server 2025 DCs, your client must establish an encrypted connection to AD DS to search, read, add, or modify confidential object attributes. What's new in Windows Server 2025 describes the new functionality:

  • Improved security for confidential attributes: DCs and AD LDS instances allow LDAP only to add, search, and modify operations that involve confidential attributes when the connection is encrypted.

This behavior doesn't affect LDAP clients that run on Windows Server 2025-based member servers or Windows 11, version 24H2-based computers. On these operating system versions, LDAP clients use encrypted sessions by default.

 

Workaround:

To work around this issue, use one of the following methods:

  • Configure your LDAP client to use the LDAP_OPT_ENCRYPT session option (or update to a client that supports this option). If you're using ldifde on Windows, use the /h switch (for example, run ldifde /h /s dc25 -i /f .\update.txt).
  • Use Windows Server 2025 or Windows 11 24H2, or a newer version, as an LDAP client. By default, these operating systems encrypt LDAP sessions. For more information about this feature, see What's new in Windows Server 2025.
  • If you can't use either of the previous methods, you can temporarily disable the encrypted session requirements. For more information, see How dsHeuristics affects the encrypted session requirements and related events in this article. Important: Please note that this method isn't secure. Use it only as a temporary step.

If you believe this information adds some value, please accept the answer so that your experience with the issue would help contribute to the whole community.

T&R

Kate.

Этот ответ помог вам?

Комментариев: 0 Без комментариев

Дополнительные ответы: 0

Сортировать по: Наиболее полезные

Ваш ответ

Автор вопроса может устанавливать для ответов пометку "Принято", а модераторы — пометку "Рекомендуется". Благодаря этому пользователям становится проще понять, какой из ответов помог решить проблему автора.