Skip to main content
AD Academy
Back to all events
2889Directory Service (DC)Security & attacksWARNLast updated:

Unsigned LDAP bind detected

What it means

A client binds to LDAP without signing/encryption — the password crosses the network exposed. Find every such client before enforcing LDAP signing.

First steps

  1. 1Set LDAP Interface Events = 2 to log every source.
  2. 2Collect IP + account, fix the app, then enforce signing and channel binding.

Related events

This reference is a starting point for investigation, not a replacement for your organisation's security policy.