Source record · tier 2 current vendor documentation
LDAP signing for Active Directory Domain Services on Windows Server
- Publisher
- Microsoft
- URL
- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/ldap-signing
- Published
- 2026-01-15
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Microsoft Learn content; Microsoft terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- Directory Service event 2887 on a domain controller reports that clients made unsigned simple binds or SASL binds without SSL/TLS, and Microsoft recommends moving such clients to LDAPS or signed LDAP. in context
- A Unified CM LDAP directory or authentication configuration that uses plain LDAP on port 389 without Use TLS is likely to have its simple binds rejected by a domain controller that enforces LDAP signing, and because Unified CM does not support StartTLS, LDAPS on 636 or 3269 is the supported way to encrypt those binds. inferred in context
- A domain controller that enforces LDAP signing rejects SASL binds that do not request signing and rejects simple binds over non-encrypted connections. in context
- New Active Directory deployments on Windows Server 2025 and later require LDAP signing by default, while Windows Server 2019 and earlier leave signing optional by default. in context
- Upgrading domain controllers from earlier Windows Server versions to Windows Server 2025 preserves the existing LDAP signing and channel binding settings. in context
Cite this source record
APA
WarmTransfer. (2026, January 15). LDAP signing for Active Directory Domain Services on Windows Server. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-ad-ds-ldap-signing
BibTeX
@misc{warmtransfer-ms-learn-ad-ds-ldap-signing,
title = {LDAP signing for Active Directory Domain Services on Windows Server},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-ad-ds-ldap-signing},
note = {Microsoft, accessed 2026-09-25}
}