Skip to main content
Version: 2.2.1-preview

AD-DNS-01 - DNS zone count should be retrievable

Overview​

DNS zones are the primary organizational units for DNS data. Understanding how many zones contain resource records helps assess:

  • Infrastructure complexity: More zones indicate a more complex DNS environment
  • Administrative boundaries: Zones often represent different administrative domains
  • Service distribution: Multiple zones may indicate delegated or distributed services
  • Security posture: Unused or empty zones may represent configuration drift

Security Recommendation​

Regularly audit DNS zones to ensure they are all necessary and properly configured. Remove unused zones and verify that zone delegation follows your organization's security policies.

How the Test Works​

This test retrieves all DNS zones and counts those that contain resource records. It provides:

  • Total number of DNS zones
  • Count of zones with records
  • Count of empty zones
  • Test-MtAdDnsEmptyZoneCount - Identifies zones with no records
  • Test-MtAdDnsZonesWithOnlySoaNs - Finds zones with only default records

Test Metadata​

FieldValue
Test IDAD-DNS-01
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsZoneCount
TagsAD, AD-DNS-01, AD.DNS

Source​

  • Pester test: tests/ad/dns/Test-MtAdDnsZoneCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsZoneCount.ps1