Not getting any LDAP 3039 events even though logging is enabled

Cormac Doyle 1 Reputation point
2020-10-01T15:45:09.137+00:00

In Microsoft official information (such as here: https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190023 and here: https://support.microsoft.com/en-ie/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirements-for-windows) it is advised to enable additional logging to find detail of clients that are sending unsecured LDAP binds to domain controllers. I have enabled this logging on domain controllers and as expected, lots of events with id 2889 are being logged providing detail.

However there are no events with id 3039 being logged. I would expect these to be logged as there are event id 3040 being logged saying that "during the previous 24 hour period, # of unprotected LDAPs binds were performed". Can anyone explain why I am not seeing any events 3039? All domain controllers have recent patches installed.

Any help appreciated.

Microsoft Entra
{count} votes

4 answers

Sort by: Most helpful
  1. Cormac Doyle 1 Reputation point
    2020-10-02T15:11:29.193+00:00

    Hi, thanks for the response.

    There are no 3039 events with any event source in the Directory Service log.

    Yet there are summary events with event id 3040 saying that "During the previous 24 hours period, 1 unprotected LDAPS binds were performed. "
    So why is there no 3039 event showing me the detail of that LDAPS bind?

    As mentioned above, all domain controllers have recent patches installed which is a prerequisite for getting the 3039 events.

    0 comments No comments

  2. Simon Berg 1 Reputation point
    2020-10-29T14:34:24.217+00:00

    Hi guys

    I'm seeing the same behavior.

    I'm investigating further...

    0 comments No comments

  3. Cormac Doyle 1 Reputation point
    2020-12-10T14:27:11.003+00:00

    Hi @Simon Berg

    I have just seen your reply now. Did you find out anything else?
    I am taking it that if there are no 3039 events then there isn't an issue. However the appearance of 3040 events is a bit worrying.

    0 comments No comments

  4. Simon Berg 1 Reputation point
    2020-12-11T08:00:04.337+00:00

    Hi @Cormac Doyle

    No unfortunately i did not find an answer.
    Maybe we should post this question to the Active Directory Team Blog

    https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/bg-p/AskDS

    0 comments No comments