1) anonymous binds are disabled by default if it is a new install. They remain enabled if it is an upgrade, and you can always enable them if you want.
2) Yes, the zimbra admin dn is a perfectly good dn to use for this type of search. If you want to use one with fewer permissions, you might try the postfix user or the replication user. The zimbra admin DN can do pretty much anything in the main db, so just be aware of that.
Zimbra :: the leader in open source messaging and collaboration