Windows Server Event: 2889

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

System Event » Windows Server Event: 2889

Event ID 2889: LDAP bind.

Description The event is logged whenever a client makes an LDAP bind that this directory Server is not configured to reject.
Category LDAP interface

The event logs the following information:

  • Client IP address
  • Number of simple binds performed without SSL/TLS
  • Number of Negotiate / Kerberos / NTLM / Digest binds without signing

Pro tips:

  • ADAudit Plus generates reports to inform the administrator when a LDAP bind occurs.
  • These reports can also be modelled as alerts to notify the administrator via E-mail or SMS.