How to count the specific IP addresses of the business systems that are connected to AD?

yanhaowen 105 Reputation points
2026-05-25T02:22:12.7533333+00:00

Hi:

How to statistically the specific IP addresses of the business systems that are connected to AD, such as identity authentication connection, organization structure and user synchronization, permission automatic management, unified identity control, etc. thanks.

Windows for business | Windows Server | Directory services | Active Directory

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Kate Pham (WICLOUD CORPORATION) 825 Reputation points Microsoft External Staff Moderator
2026-05-25T07:15:45.62+00:00

Hello,

Thank you for contacting the Microsoft Q&A community! 😊

To identify and count the IP addresses of business systems connected to Active Directory (such as identity authentication services, organizational structure queries, user synchronization, permission management, and unified identity control), you can use LDAP query to trigger Event ID 2889 in Event Viewer.

Please refer to the bellow instructions:

1. Enable LDAP events on the Domain Controller

Run the following command as Administrator on your Domain Controller:

reg add HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics /v "16 LDAP Interface Events" /t REG_DWORD /d 2 /f

This setting enables the following events:

  • Event ID 2887 – Summary of unsigned LDAP binds (logged every 24 hours)
  • Event ID 2889 – Detailed information, including client IP address and identity

After enabling this setting:

  • Open Event Viewer
  • Navigate to: Applications and Services Logs → Directory Service
  • Filter the log for Event ID 2889

Note: These events are only recorded after logging is enabled and LDAP activity occurs. Historical data prior to enabling logging will not be available.

2. Extract IP addresses using PowerShell

You can use the following PowerShell script to extract and summarize client IP addresses from Event ID 2889:

Get-EventLog -LogName "Directory Service" -InstanceId 2889 -Newest 1000 |
Select-Object -ExpandProperty Message |
Select-String -Pattern "Client IP address:\s+([^\s]+)" |
ForEach-Object { ($_ -split ":")[1].Trim() } |
Group-Object |
Sort-Object Count -Descending |
Select-Object Name, Count

This script will help you:

  • Identify all client IP addresses connecting via LDAP
  • Count the number of connections per IP
  • Prioritize investigation of high-volume systems

I hope this information is helpful. If it answers your question, please consider selecting "Accept the Answer" to assist others in the community. 😊

T&R,

Kate.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. AI answer

    2026-05-25T02:22:27.41+00:00

    Active Directory itself does not maintain a simple built-in report of “all business systems and their IPs that connect for authentication/sync/permissions.” To get this information, network and directory data must be combined and analyzed.

    A practical approach is:

    1. Collect IP and system information from the network
      • Document IP subnets and locations used by business systems.
      • In Windows Server environments, this is part of standard AD DS planning: AD DS associates workstations and servers with sites by comparing their IP addresses with defined subnets.
      • Work with the networking team to obtain:
        • Subnet definitions (IPv4 and IPv6).
        • Known IP ranges for application servers, middleware, and integration platforms.
    2. Use AD-related logs to identify connecting IPs
      For “identity authentication connection” and related operations, use:
      • Domain controller security logs (Kerberos/NTLM logon events) to see client IPs that authenticate against AD.
      • AD FS / Web Application Proxy logs if federated authentication is used. For example, in AD FS scenarios, client IPs and proxies are visible and can be aggregated for reporting (similar to how the Risky IP report aggregates failed sign-in IPs).
      • Network traces (for targeted troubleshooting) to see which IPs perform LDAP, SMB, and RPC traffic during domain join and authentication operations.
    3. Aggregate and analyze IPs
      • Export logs (Security logs, AD FS logs, network traces) to a SIEM or log analytics platform.
      • Filter for authentication and directory access events (Kerberos, NTLM, LDAP bind, AD FS sign-in).
      • Summarize by source IP to get a list of IPs that are actively connecting to AD for authentication and directory operations.
      • Cross-reference these IPs with the subnet/location documentation to identify which ones belong to business systems vs. user workstations.
    4. Maintain an IP address management (IPAM) process
      • Use IP Address Management (IPAM) tools on Windows Server to centrally manage IP address space, DHCP, and DNS.
      • With IPAM, correlate DNS names, DHCP leases, and IP ranges to identify and track business systems that interact with AD.
    5. For cloud-integrated scenarios (Microsoft Entra ID)
      • When AD is integrated with Microsoft Entra ID and cloud services, use sign-in logs and reports (for example, risky IP or sign-in IP reports) to identify external IPs used by applications and services that authenticate against Entra ID and, indirectly, AD.
      • Compare these IPs with expected ranges and add them to named locations where appropriate.

    This combination of subnet documentation, AD/DC logs, AD FS/WAP logs, network traces, and IPAM provides a statistical view of which specific IP addresses (servers and systems) are connecting to AD for authentication, directory synchronization, and related identity operations.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?