The recommended approach is to harden the domain controllers by enforcing LDAP signing and reviewing LDAP channel binding before moving to stricter enforcement.
- Review the current hardening state on the domain controllers.
- Check Domain controller: LDAP server signing requirements.
- Check Domain controller: LDAP server channel binding token requirements.
- Microsoft states that the March 10, 2020 updates and later updates do not automatically change the default LDAP signing or LDAP channel binding policies on new or existing domain controllers.
- Audit before enforcing.
- Review Directory Service event log entries for LDAP signing:
- 2886: server is not enforcing LDAP signing.
- 2887: unprotected binds were accepted.
- 2888: unprotected binds were rejected after Require Signing is enabled.
- 2889: identifies clients that do not use signing on port 389 when higher logging is enabled.
- Review LDAP channel binding audit events:
- 3039, 3040, 3041 for CBT-related activity.
- On Windows Server 2022, the August 8, 2023 update also added audit events 3074 and 3075 for clients that cannot use LDAP channel binding tokens.
- Review Directory Service event log entries for LDAP signing:
- Start with a compatibility-focused channel binding configuration.
- If using the LdapEnforceChannelBinding registry entry, Microsoft recommends value 1 to maximize compatibility with older operating system versions.
- Value 0 explicitly disables the setting.
- The LDAP server responds dynamically to changes to this registry entry, so a restart is not required after applying the registry change.
- Risk: on Windows Server 2008 and older systems, required prerequisite protection must be installed first; otherwise LDAPS connections can fail with LDAP error 81 - LDAP_SERVER_DOWN.
- Identify and reduce the LDAP workload that is driving CPU spikes.
- Run Active Directory Diagnostics in Performance Monitor while the issue is occurring:
- Open Server Manager or run Perfmon.msc.
- Go to Diagnostics > Reliability and Performance > Data Collector Sets > System.
- Start Active Directory Diagnostics.
- After collection and report compilation, review Reports > System > Active Directory Diagnostics.
- In the report, check:
- Diagnostic Results for general performance concerns.
- Active Directory for what the domain controller is busy doing, including LDAP queries affecting performance.
- Network to identify remote clients communicating most with the domain controller.
- Run Active Directory Diagnostics in Performance Monitor while the issue is occurring:
- Review query behavior before assuming policy enforcement alone will solve the CPU issue.
- Focus on top calling clients and identify the source of excessive LDAP workload.
- Verify clients are using site-optimal domain controllers.
- Work with application owners to reduce query frequency and use caching.
- Optimize LDAP query syntax, reduce returned attributes, and narrow the search base.
- Add Active Directory attribute indexes only when required, noting that this increases database size and can temporarily delay replication during index build.
In practice, the safest sequence is:
- audit current unsigned and CBT-incompatible clients,
- identify the systems generating excessive LDAP searches,
- remediate or reconfigure those clients and applications,
- then enforce LDAP server signing requirements and tighten LDAP server channel binding token requirements.
- 2020, 2023, and 2024 LDAP channel binding and LDAP signing requirements for Windows (KB4520412)
- 2020, 2023, and 2024 LDAP channel binding and LDAP signing requirements for Windows (KB4520412)
- 2020, 2023, and 2024 LDAP channel binding and LDAP signing requirements for Windows (KB4520412)
- KB4034879: Use the LdapEnforceChannelBinding registry entry to make LDAP authentication over SSL/TLS more secure
- How to troubleshoot high Lsass.exe CPU utilization on Active Directory Domain Controllers
- Use Event1644Reader.ps1 to analyze LDAP query performance in Windows Server