Active Directory – Check communication (portqueryUI)

Overview

With network segmentation, domain controllers often have to configured on a firewall. How do you test, verify and document the functioniality or errors?

You often have to run tests, repeat them and document them. I like to use the Microsoft port query tool for this and add the GUI – graphical user interface – for better visibility.

The tool is available from Microsoft and allows various functions to be executed and run against DNS names of systems or IP addresses.

Download and Installation of portqueryUI

To do this, we download the programme directly from Microsoft via this link or search for ‘portqueryUI’ in the search engine of our choice.

Execute the downloaded file and accept the licence agreement. Then select the path for unpacking the files. In the example, I unzip this into my user directory under Documents on the test server.

portqueryui entpacken der Installationsdateien
portqueryui unzip of the installer files

Configuration

Then set the programme so that the domain controller to be tested is set as the destination IP and select the Domain and Trusts service.

The tool then automatically checks all relevant network ports to the domain controller and reports if certain communication does not work.

PortqueryUI Testen der Verbindung zum Domain Controller
Test the connection to a Domain Controller

Summary on how to check Active Directory communication with Port Query

For me, an unjustly forgotten ‘treasure’ of a tool. I still like to use it and will do so again and again. For more tools to check connectivity take a look at WinMTR here.

Spread the knowledge
Avatar for Andreas Hartig
Andreas Hartig - MVP - Cloud and Datacenter Management, Microsoft Azure

Related Posts

dragon it system engineer grc benchmark

Windows DNS Performance Testing

DNS issues don’t always show up as clear outages. Often they show up as annoying browser behaviour like “random delays on first page load”, “sometimes it works, sometimes it spins”,…

Spread the knowledge
Read more
IT Security Dragon reading Windows Event Logs

Windows Server Event Log and Event Log Policies

Windows Server Event Log for most teams are only used when something already smells like incident:💥 DC misbehaving,💥 file server “mysteriously slow”,💥 SOC asking for “all the logs you have…

Spread the knowledge
Read more
notepad addons 2025 hero

Notepad++ – Most important AddOns 2025

Notepad++ is my favourite notebook and editor is actually perfect, but it can always be better. For this reason, there are a few “quality of life” improvements that I use…

Spread the knowledge
Read more
Technitium DNS Server on Windows

Homelab – Build a robust DNS foundation – Part 2 using Technitium DNS Server on Windows

Let’s create an improved version of the Technitium DNS server for Windows. Some time ago, I wrote a DNS guide to help you get started with your home laboratory. This…

Spread the knowledge
Read more
Tinyproxy and a dragon IT architect from the shadowrun world looking at a large screen with graphs on it

Tinyproxy on Hyper-V – new Ubuntu 24.04

A Linux VM with Proxy, such as tinyproxy, can be used to reduce bandwidth as it caches frequently requested websites. Today we want to configure a Linux VM with a Proxy and deploy…

Spread the knowledge
Read more
COM Port Management and a dragon IT architect from the shadowrun world looking at a com port and a manufacturing floor

Windows – easy COM Port Management without Admin Rights with Windows 10 & 11

COM Port Management with no administrator rights is a challenge. You might have noticed that I am currently involved in IT and OT discussions. During OT modernization, I encountered a…

Spread the knowledge
Read more