AD-DCOMP-09 - Computer DNS zone details should be retrievable
Overviewโ
- Detailed analysis of DNS zone distribution provides visibility into Active Directory topology and helps identify potential configuration issues or security concerns related to DNS.
Security and Operational Value:
- Topology Mapping: Understand how computers are distributed across DNS domains
- Disjoint Namespace Detection: Identify computers in unexpected DNS zones
- Configuration Validation: Verify computers are in appropriate zones
- Compliance Verification: Ensure DNS configuration meets organizational standards
Potential Issues Identified:
- Computers in incorrect DNS zones
- Disjoint namespace misconfigurations
- Orphaned computer accounts
- DNS registration failures
Security Recommendationโ
-
Zone Assignment Review:
- Verify computers are in appropriate DNS zones
- Investigate computers in unexpected zones
- Document legitimate multi-zone scenarios
-
DNS Configuration Audit:
- Regular review of DNS zone configuration
- Validate DNS delegation settings
- Check for stale or orphaned records
-
Remediation:
- Move computers to correct zones if misconfigured
- Delete stale computer accounts
- Fix DNS registration issues
How the Test Worksโ
This test provides detailed analysis:
- Breakdown of computers by DNS zone
- Counts per zone with percentages
- List of computers without DNS host names
- Distribution statistics
Related Testsโ
Test-MtAdComputerDnsZoneCount- DNS zone count summaryTest-MtAdComputerDnsHostNameCount- DNS host name coverageTest-MtAdAllowedDnsSuffixesCount- DNS suffix configuration
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DCOMP-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Security |
| PowerShell test | Test-MtAdComputerDnsZoneDetails |
| Tags | AD, AD-DCOMP-09, AD.Security |
Sourceโ
- Pester test:
tests/ad/security/Test-MtAdComputerDnsZoneDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/security/Test-MtAdComputerDnsZoneDetails.ps1

