AD-DNS-01 - DNS zone count should be retrievable
Overviewβ
DNS zones are the primary organizational units for DNS data. Understanding how many zones contain resource records helps assess:
- Infrastructure complexity: More zones indicate a more complex DNS environment
- Administrative boundaries: Zones often represent different administrative domains
- Service distribution: Multiple zones may indicate delegated or distributed services
- Security posture: Unused or empty zones may represent configuration drift
Security Recommendationβ
Regularly audit DNS zones to ensure they are all necessary and properly configured. Remove unused zones and verify that zone delegation follows your organization's security policies.
How the Test Worksβ
This test retrieves all DNS zones and counts those that contain resource records. It provides:
- Total number of DNS zones
- Count of zones with records
- Count of empty zones
Related Testsβ
Test-MtAdDnsEmptyZoneCount- Identifies zones with no recordsTest-MtAdDnsZonesWithOnlySoaNs- Finds zones with only default records
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsZoneCount |
| Tags | AD, AD-DNS-01, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsZoneCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsZoneCount.ps1

