For my environment, it’s more a policy issue than a technical one. The folks in charge of our AD environment have decided that anonymous binds won’t be allowed, period.
Our AD group creates special bind users for situations like this, whose privileges are very limited (probably functionally equivalent to that of an anonymous user). Philosophically, I agree that it’s unwise to keep cleartext passwords around (or stored in an easily-reversible hash), but I’m not sure there’s a functional alternative in this case.