Open Internet by MindsNet
Identifying Unsigned LDAP Bindings from Windows 11 Clients
Event ID 2889 LDAP unsigned bindings are being generated from Windows 11 Enterprise end-user workstations, causing concern about potential security vulnerabilities. The issue seems to stem from standard domain activity, but the exact process making these unsigned LDAP calls is unclear. There is a need to identify which process on the client is making these calls and to determine if this is a normal occurrence.
Computing & Technology, Information Technology, IT Security