Active Directory

For EmpowerID to communicate with Active Directory environments, the following ports must be open:

Internal EmpowerID Communications

The EmpowerID Management Console Windows desktop client requires the following ports be open:


EmpowerID server to server communications require the following ports be open:


EmpowerID server to SQL Database communications require the following ports be open:



The EmpowerID WAM/Reverse Proxy does not require any communication with the Microsoft SQL database. The Reverse Proxy retrieves all of its configuration data by calling the EmpowerID REST API on any front-end servers.


The below two images depict the EmpowerID Communications and Connectivity architecture. The first shows the architecture without EmpowerID WAM/Reverse Proxy, while the second shows the architecture with EmpowerID WAM/Reverse Proxy.

Figure 1: EmpowerID Communications and Connectivity Architecture

Figure 2: EmpowerID Communications and Connectivity architecture with WAM/Reverse Proxy module




In addition to the above, for password resets you may need to open TDP/UDP 135, as well as all RPC dynamic ports. For more information, see the following Microsoft topics:





Hardware Requirements and Sizing

Certificate Requirements

Access Rights and Service Accounts