Skip to main content
Version: 2.2.1-preview

AD-DCOMP-07 - Computer DNS host name count should be retrievable

Overviewโ€‹

  • DNS host names (the dNSHostName attribute) are essential for proper Active Directory functionality, particularly for Kerberos authentication and service principal name (SPN) registration.

Security Implications:

  • Kerberos Authentication: Required for proper Kerberos ticket requests
  • SPN Registration: Service Principal Names depend on valid DNS host names
  • Name Resolution: Critical for service discovery and connectivity
  • Certificate Management: SSL/TLS certificates often depend on DNS names

Missing DNS Host Names May Indicate:

  • Improper computer provisioning
  • Legacy systems from older AD versions
  • Configuration errors during domain join
  • Incomplete computer account setup

Security Recommendationโ€‹

  1. Ensure Proper Configuration:

    • All computers should have valid DNS host names
    • DNS names should match the computer's actual network name
    • Regular validation of DNS registration
  2. DNS Integration:

    • Enable dynamic DNS updates for domain members
    • Verify DNS records match AD computer accounts
    • Monitor for DNS registration failures
  3. Remediation:

    • Update computers missing DNS host names
    • Delete stale computer accounts without DNS names
    • Investigate provisioning process if widespread issue

How the Test Worksโ€‹

This test counts computers with and without the dNSHostName attribute populated and reports:

  • Total computers
  • Computers with DNS host names
  • Computers without DNS host names
  • Percentage coverage
  • Test-MtAdComputerDnsZoneCount - DNS zone distribution
  • Test-MtAdComputerDnsZoneDetails - Detailed DNS zone analysis
  • Test-MtAdComputerSpnSetCount - SPN configuration check

Test Metadataโ€‹

FieldValue
Test IDAD-DCOMP-07
SeverityInfo
SuiteActive Directory
CategoryAD.Security
PowerShell testTest-MtAdComputerDnsHostNameCount
TagsAD, AD-DCOMP-07, AD.Security

Sourceโ€‹

  • Pester test: tests/ad/security/Test-MtAdComputerDnsHostNameCount.Tests.ps1
  • PowerShell source: powershell/public/ad/security/Test-MtAdComputerDnsHostNameCount.ps1