Audit LDAP signing by checking the effective setting on every domain controller, identifying clients that still make unsigned binds, remediating them, and then verifying that enforcement rejects unprotected traffic. Do not treat LDAP signing readiness as proof that clients are ready for LDAP channel-binding enforcement; these are separate controls.
What LDAP signing protects—and what it can reject
LDAP signing protects the integrity of LDAP traffic. When a domain controller requires signing, it can reject unsigned SASL binds and simple binds sent over connections that do not use SSL/TLS. A policy value alone does not establish whether clients are compatible or whether enforcement is working; the audit must cover both the domain controllers and the client traffic they handle.
1. Inventory domain controllers and check effective policy
List every domain controller in scope, then compare its effective policy with the intended configuration. In Group Policy, review Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Domain controller: LDAP server signing requirements. The enforcement choice is Require signing. The separate client-side setting, Network security: LDAP client signing requirements, applies to clients; Microsoft recommends configuring clients before requiring signing on servers.
Check the policy representation on each domain controller at HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters. Microsoft maps LDAPServerIntegrity value 1 to None and 2 to Require Signing. Investigate any mismatch between the effective policy and registry value rather than assuming that the intended GPO has taken effect everywhere. See Microsoft’s Group Policy procedure and the KB4520412 policy and registry reference.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Account for server release and deployment history when interpreting defaults. Microsoft says new Active Directory deployments on Windows Server 2025 and later require signing by default through a separate enforcement policy, while upgraded deployments retain their existing policy. Older releases have different defaults. Verify the applicable behavior for the actual Windows Server version and whether the domain was newly deployed or upgraded; do not infer the whole domain’s state from a general default.
2. Find clients making unsigned binds
Start with Event 2887
On each domain controller, open Event Viewer > Applications and Services Logs > Directory Service and inspect Event 2887. When unsigned binds are accepted under a policy of None, this periodic summary reports unsigned simple binds and SASL binds that did not request signing. Microsoft describes the summary as covering the preceding 24 hours; its support reference says Event 2887 is triggered when at least one unprotected bind completed while policy is None. A quiet summary interval is not evidence that every rarely used application or failover path is compatible.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Enable client-specific Event 2889 records
For attribution, set HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSDiagnostics16 LDAP Interface Events to 2 (Basic) on the domain controller, then monitor Event 2889 in the Directory Service log. It records client-specific details, including the client IP address and attempted identity; the binding type indicates whether the attempt was an unsigned SASL bind or an unprotected simple bind. Microsoft’s event description refers to a SASL bind without requested signing or a simple bind over a clear-text, non-SSL/TLS connection. See Microsoft’s event troubleshooting guidance.
Use the IP address and identity as investigation clues, not as definitive identification of the responsible process. Correlate them with asset inventory, application ownership, and, for non-Windows appliances, the relevant device or software provider. Observe representative business cycles, scheduled jobs, failover paths, and infrequently used applications. Microsoft advises confirming that such events do not occur for an extended period before rejecting unsigned binds.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
3. Remediate clients before requiring signing
For each affected client, identify the application or device performing the bind and update its configuration to request LDAP signing or use an appropriate protected connection. Microsoft warns that clients relying on unsigned SASL binds or simple binds without SSL/TLS can stop working after the server rejects those binds. For non-Windows devices and appliances, coordinate the change with the application, operating-system, or device provider.
- Use the Event 2889 details and your asset records to locate the application or device owner.
- Have the owner configure the client to request signing, or move the simple bind to an appropriate SSL/TLS-protected connection.
- Repeat observation across representative workloads and investigate any remaining unsigned-bind records before changing the server requirement.
When client remediation is complete, set the domain-controller policy to Require signing and allow Group Policy to refresh. Microsoft’s Group Policy guidance describes the policy workflow. This domain-controller policy path is for AD DS; AD LDS uses a separate per-instance registry configuration.
Rank #4
4. Monitor rejections and verify enforcement
After the requirement is active, review Event 2888 on domain controllers. It is the periodic summary for unprotected binds rejected under the required-signing setting. Event 2889 can also provide client attribution when the diagnostic level remains enabled. Investigate rejected traffic and check application health; a registry or policy value by itself does not demonstrate that the migration is complete.
For a controlled basic test, Microsoft documents using Ldp.exe to connect to the domain controller on port 389 and attempt a simple bind. With signing enforced, the unsigned simple bind should fail with a Strong Authentication Required error. Run this only as a controlled check. It tests that bind scenario, not every application, protocol, or network path used in production, so continue monitoring production logs after the test.
5. Audit LDAP channel binding separately
LDAP channel binding ties authentication to a TLS session by using a Channel Binding Token (CBT). It is especially relevant to authentication over SSL/TLS, but it is not the same control as LDAP signing. Passing the signing audit does not establish client readiness for channel-binding enforcement.
Channel binding has its own policy and registry setting, LdapEnforceChannelBinding, with values 0 (Never), 1 (When Supported), and 2 (Always). Its compatibility checks use different events: Event 3039 concerns a TLS bind whose CBT validation fails, while Events 3074 and 3075 audit binds that would fail or lack channel-binding information under enforcement. Microsoft states that these audit events have update and policy prerequisites: applicable 2023/2024 updates for Windows Server 2022 and 2019, and channel binding set to When Supported or Always for Events 3039, 3074, and 3075. Check the current KB4520412 prerequisites for the server release in use before relying on those events.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

