Going back to the original question, can ATA provide any visibility into read activity against the
ms-Mcs-AdmPwd attribute? At least in our environment, access of more than one password attribute per hour(or even day) would be pretty unusual.
It's my understanding that the
ms-Mcs-AdmPwd attribute access isn't audited, so ATA's LDAP access would seem to give it a uniquely good vantage point.