AD-DCOMP-08 - Computer DNS zone count should be retrievable
Overviewβ
- Understanding DNS zone distribution across domain computers helps identify network topology, disjoint namespace configurations, and potential DNS-related security issues.
Security and Operational Insights:
- Disjoint Namespaces: Multiple DNS zones may indicate disjoint namespace configurations
- Multi-Domain Environments: Helps understand domain and forest structure
- DNS Security: Identifies zones that need DNSSEC or other security measures
- Network Segmentation: May reveal network segmentation or perimeter boundaries
Common Scenarios:
- Single-domain environments typically have one DNS zone
- Multi-domain forests have multiple zones
- Disjoint namespaces require special configuration
- External DNS zones for perimeter networks
Security Recommendationβ
-
Validate Zone Configuration:
- Ensure all DNS zones are intentional and documented
- Review disjoint namespace configurations
- Verify DNS zone delegation is correct
-
DNS Security:
- Enable DNSSEC for all DNS zones
- Implement secure dynamic updates
- Monitor for unauthorized zone transfers
-
Documentation:
- Document all DNS zones and their purposes
- Maintain network topology diagrams
- Review during security audits
How the Test Worksβ
This test extracts DNS zones from computer dNSHostName attributes and:
- Counts unique DNS zones
- Lists all zones in use
- Identifies computers without DNS host names
Related Testsβ
Test-MtAdComputerDnsHostNameCount- DNS host name coverageTest-MtAdComputerDnsZoneDetails- Detailed zone breakdownTest-MtAdDnsZoneCount- DNS server zone analysis
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DCOMP-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Security |
| PowerShell test | Test-MtAdComputerDnsZoneCount |
| Tags | AD, AD-DCOMP-08, AD.Security |
Sourceβ
- Pester test:
tests/ad/security/Test-MtAdComputerDnsZoneCount.Tests.ps1 - PowerShell source:
powershell/public/ad/security/Test-MtAdComputerDnsZoneCount.ps1

