To hide an Active Directory attribute from ordinary users, mark the attribute confidential by setting bit 7 of its schema searchFlags value: decimal 128 (hexadecimal 0x80). A reader must then have both ordinary READ_PROPERTY permission and CONTROL_ACCESS for that attribute or its property set. This is an authorization check, not encryption of the value stored in the directory.
What the confidentiality bit does
Active Directory keeps metadata for every attribute in an attributeSchema object. Microsoft calls the confidentiality flag fCONFIDENTIAL. Its value is bit 7 of searchFlags:
| Schema setting | Value | Effect |
|---|---|---|
searchFlags bit 7 |
Decimal 128; hexadecimal 0x80 |
Requires the additional confidential-attribute access check |
Microsoft states: “Bit 7 (128) designates the attribute as confidential.” See Microsoft’s implementation guidance and the MS-ADTS specification.
It hides reads; it does not encrypt data
The bit changes authorization for access through Active Directory protocols. It does not encrypt the attribute at rest, remove it from the database, or make it invisible to every privileged path. Administrators and principals explicitly granted the required right can still read it.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Which permissions a reader needs
A requester must satisfy both checks:
READ_PROPERTYon the object and attribute.CONTROL_ACCESSfor the confidential attribute or the property set that contains it.
Microsoft notes that, by default, only administrators have CONTROL_ACCESS permissions to all objects. You can delegate that right to a specific application account or group instead of making the account an administrator. Grant only the scope and principals that genuinely need the value.
How to set searchFlags to 128
-
Identify the attribute
Choose the existing attribute that contains the sensitive value, or design a dedicated schema attribute for new data. Confirm its LDAP display name and locate its corresponding
attributeSchemaobject. -
Read the current value
Record the existing integer in
searchFlagsbefore changing it. Do not overwrite other search flags that the attribute already uses. -
Add the confidentiality bit
Calculate the new value with Microsoft’s formula:
Recommended: Update Every Outdated Driver on Your PC in One Scan - Free →Recommended: PC Feels Slow? A Free Scan Shows What's Dragging Windows Down →Recommended: Crashes or Glitches? A Free Driver Scan Usually Finds the Culprit →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.new searchFlags = current searchFlags + 128For example, a current value of
1becomes129. The example is arithmetic only; preserve every existing flag. -
Make the schema change through change control
Microsoft documents Ldp.exe, Adsiedit.msc, and LDIF-based updates for schema work. Use the method approved for your forest, record the original value, and have a rollback that restores that value if testing fails.
-
Delegate access deliberately
Give the application or administrator group that must read the value an explicit or inheritable
CONTROL_ACCESSaccess control entry, while retaining the necessaryREAD_PROPERTYpermission. Dsacls.exe can assign the permission; verify the resulting ACE rather than assuming inheritance is correct. -
Test both authorization paths
Run searches as an account that should be denied and one that should be allowed. Include searches whose filter references the protected attribute, not just requests that list it in the returned attributes. Test the real application account and any synchronization service account.
Free tools Windows power users keep installed
One-click scans. No signup required.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Prerequisites and risks
All domain controllers must enforce the feature
Microsoft’s implementation guidance says enforcement is available on domain controllers running Windows Server 2003 SP1 or later. A mixed environment containing older controllers can still expose a confidential value. Inventory domain-controller versions and do not treat one upgraded controller as proof that the forest is protected.
Rank #2
Schema changes are forest-wide
An attributeSchema change affects the forest, not just one organizational unit. Test first in a lab that mirrors production, including domain-controller versions, replication topology, delegated groups, applications, and synchronization jobs.
ACL inheritance can overexpose or break the value
An inherited CONTROL_ACCESS ACE can grant more readers than intended; an incorrectly scoped ACE can block a required application. Review effective permissions for representative users and service accounts after replication.
Why an LDAP query might still reveal the attribute
The account is privileged or delegated
The confidentiality bit is not a blanket prohibition. An administrator or a principal granted CONTROL_ACCESS, together with READ_PROPERTY, is expected to read the value.
A legacy domain controller answered the request
If any controller handling the request does not enforce confidential-attribute checks, the value may be exposed. Confirm that every controller capable of servicing the client supports the feature and that replication has completed.
The request uses a different data path
Validate ordinary LDAP searches, Global Catalog use, DirSync, and application-specific APIs separately. The MS-ADTS specification describes a DirSync case in which object-security flags can cause a confidential attribute to be returned with an empty value. An empty result is therefore not equivalent to proof that the attribute is absent, and synchronization tools need their own security test.
The test account or permission model is wrong
Check effective permissions, group membership, nested groups, and the target attribute’s property set. Having READ_PROPERTY alone is insufficient; having a broad delegated right may be enough to make the read succeed.
LDAP transport and dSHeuristics
The current MS-ADTS dSHeuristics specification says the setting that disables encryption controls confidential-attribute searches, modifications, and adds. When no disable bits are set, those operations require encrypted transport or SASL encryption.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesKeep LDAP signing and channel encryption enabled. Do not weaken a forest-wide heuristic merely to accommodate an old client; update or reconfigure the client and then retest its confidential-attribute operations.
Choosing the right protection model
| Design option | Granularity | Delegation model | Main compatibility concern | Operational consideration |
|---|---|---|---|---|
| Confidentiality bit | Per attribute | Explicit or inherited CONTROL_ACCESS ACE, plus READ_PROPERTY |
Every servicing domain controller must enforce the feature; protocol paths such as DirSync need testing | Requires a forest-wide schema change and careful ACL review |
| Broader object or OU ACL changes | Object or container scope, potentially covering multiple attributes | Conventional ACL inheritance and object-level permissions | May affect unrelated attributes and applications that need ordinary directory reads | Can avoid a schema edit but provides less attribute-level isolation |
Use the confidentiality bit when the requirement is specifically to restrict one attribute and you can manage schema and access-control changes safely. Use broader ACLs only when the intended boundary is an object or organizational unit rather than a single value.
Quick Recap
Production-readiness checks
- Document the original and new
searchFlagsvalues and an approved rollback. - Confirm every domain controller supports enforcement and has received the schema change.
- Verify denied and allowed reads with real user and service accounts.
- Test LDAP searches, filters, synchronization, and application APIs over encrypted sessions.
- Monitor denied reads and review effective permissions after any group or inheritance change.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

