Hi sir.
You might encounter unexpected results for operations on confidential attributes on Windows Server 2025 DCs. Allow me to explain new requirements for using LDAP clients to access confidential attributes while they're connected to Windows Server 2025-based domain controllers (DCs).
When you search for or edit Active Directory Domain Services (AD DS) objects, you notice the following behavior:
- When you run a Lightweight Directory Access Protocol (LDAP) search request against a Windows Server 2025-based DC, the resulting attribute list doesn't include confidential attributes. However, if you run the same LDAP query against a DC that runs on Windows Server 2022 or earlier, you obtain a full attribute list in the response.
Cause:
Because of new functionality in Windows Server 2025 DCs, your client must establish an encrypted connection to AD DS to search, read, add, or modify confidential object attributes. What's new in Windows Server 2025 describes the new functionality:
- Improved security for confidential attributes: DCs and AD LDS instances allow LDAP only to add, search, and modify operations that involve confidential attributes when the connection is encrypted.
This behavior doesn't affect LDAP clients that run on Windows Server 2025-based member servers or Windows 11, version 24H2-based computers. On these operating system versions, LDAP clients use encrypted sessions by default.
Workaround:
To work around this issue, use one of the following methods:
- Configure your LDAP client to use the LDAP_OPT_ENCRYPT session option (or update to a client that supports this option). If you're using ldifde on Windows, use the
/hswitch (for example, runldifde /h /s dc25 -i /f .\update.txt). - Use Windows Server 2025 or Windows 11 24H2, or a newer version, as an LDAP client. By default, these operating systems encrypt LDAP sessions. For more information about this feature, see What's new in Windows Server 2025.
- If you can't use either of the previous methods, you can temporarily disable the encrypted session requirements. For more information, see How dsHeuristics affects the encrypted session requirements and related events in this article. Important: Please note that this method isn't secure. Use it only as a temporary step.
If you believe this information adds some value, please accept the answer so that your experience with the issue would help contribute to the whole community.
T&R
Kate.