Hello,
Thank you for contacting the Microsoft Q&A community! 😊
To identify and count the IP addresses of business systems connected to Active Directory (such as identity authentication services, organizational structure queries, user synchronization, permission management, and unified identity control), you can use LDAP query to trigger Event ID 2889 in Event Viewer.
Please refer to the bellow instructions:
1. Enable LDAP events on the Domain Controller
Run the following command as Administrator on your Domain Controller:
reg add HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics /v "16 LDAP Interface Events" /t REG_DWORD /d 2 /f
This setting enables the following events:
- Event ID 2887 – Summary of unsigned LDAP binds (logged every 24 hours)
- Event ID 2889 – Detailed information, including client IP address and identity
After enabling this setting:
- Open Event Viewer
- Navigate to: Applications and Services Logs → Directory Service
- Filter the log for Event ID 2889
Note: These events are only recorded after logging is enabled and LDAP activity occurs. Historical data prior to enabling logging will not be available.
2. Extract IP addresses using PowerShell
You can use the following PowerShell script to extract and summarize client IP addresses from Event ID 2889:
Get-EventLog -LogName "Directory Service" -InstanceId 2889 -Newest 1000 |
Select-Object -ExpandProperty Message |
Select-String -Pattern "Client IP address:\s+([^\s]+)" |
ForEach-Object { ($_ -split ":")[1].Trim() } |
Group-Object |
Sort-Object Count -Descending |
Select-Object Name, Count
This script will help you:
- Identify all client IP addresses connecting via LDAP
- Count the number of connections per IP
- Prioritize investigation of high-volume systems
I hope this information is helpful. If it answers your question, please consider selecting "Accept the Answer" to assist others in the community. 😊
T&R,
Kate.