Every windows admin should be aware of what's coming March 2020:
https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows
The general recommendation at this point is to make this registry key adjustment to all your domain controllers:
# Enable Simple LDAP Bind Logging
Reg Add HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics /v "16 LDAP Interface Events" /t REG_DWORD /d 2
Once this has been done, you can monitor the event log on your DCs for event ID 2889 under the directory service log . . or you can run my script to check all your servers, and create a single report of all connections over the last 24 hours.
My script is based off the nice work by "Russell Tomkins" from Microsoft, his version available here:
https://github.com/russelltomkins/active-directory
The differences between our versions, his checks a single dc, mine checks the domain gets a list of DC's to check, then creates a report of all connections across them all.
The only parts to edit, are the lines for where to find the OU for he domain controllers, enter your domain name. And the path for the output CSV needs to exist as well.
hope it helps
**********start script***************
import-module activedirectory
cls
echo " "
echo " "
#
# Create shell arrays for holding the 2 needed data sets.
#
$Comps=@()
$Data=@()
#
# Gather list of Domain controllers
#
$Comps=get-adcomputer -filter * -searchbase "OU=Domain Controllers,DC=YOURDOMAINNAMEGOESHERE!!!,DC=com" | Sort Name
$compstocheck=$comps.count
#
# Gather data from each server's event logs, pull into single array.
#
echo " "
write-host "I found $compstocheck domain controllers, and will start checking their event data one by one" -foregroundcolor green
echo " "
ForEach ($DC in $Comps)
{
$dcname=$DC.name
echo " "
write-host "Pulling events from $dcname" -foregroundcolor Yellow
echo " "
$hours=24
$Events=get-winevent -computername $dcname -filterhashtable @{Logname='Directory Service';Id=2889; StartTime=(get-date).AddHours("-$hours")} -ea silentlycontinue
write-host "Processing events from $dcname" -foregroundcolor Cyan
echo " "
ForEach ($Event in $Events)
{
$Etime=$Event.Timecreated
$eventXML = [xml]$Event.ToXml()
$Client = ($eventXML.event.EventData.Data[0])
$IPAddress = $Client.SubString(0,$Client.LastIndexOf(":"))
$Port = $Client.SubString($Client.LastIndexOf(":")+1)
$User = $eventXML.event.EventData.Data[1]
Switch ($eventXML.event.EventData.Data[2])
{
0 {$BindType = "Unsigned"}
1 {$BindType = "Simple"}
}
$Row="" | select DCname,IPAddress,Port,User,BindType,TimeCreated
$Row.DCname=$dcname
$Row.IPAddress=$IPAddress
$Row.Port=$Port
$Row.User=$User
$Row.BindType=$BindType
$Row.TimeCreated=$ETime
#
# Add the found event data to the master array
#
$Data +=$Row
}
write-host "Completed processing all related events for $DCname, moving on" -foregroundcolor Green
echo " "
}
#
#
write-host "Generating report" -foregroundcolor Green
echo " "
$Reportcsv="C:\SimpLdap\SimpleLdapReport.csv"
#
$Data | export-csv "$Reportcsv" -notypeinformation
#
*************End Script***********
No comments:
Post a Comment