AD-DNS-04 - Root server incorrect IP details should be retrievable
Overviewβ
Detailed information about incorrect root server configurations is essential for:
- Rapid remediation: Knowing exactly which servers are misconfigured enables quick fixes
- Root cause analysis: Understanding the scope helps identify how the misconfiguration occurred
- Security incident response: Unexpected changes may indicate compromise or attack
- Compliance documentation: Detailed records support audit requirements
Security Recommendationβ
When incorrect root server IPs are detected:
- Document all discrepancies
- Update root hints to match official IANA addresses
- Investigate the cause of the discrepancy
- Implement monitoring to detect future unauthorized changes
How the Test Worksβ
This test provides detailed information about each root server that has an incorrect IP address, including:
- Configured IP address
- Expected (correct) IP address
- Status of all root servers
Related Testsβ
Test-MtAdDnsRootServerIncorrectCount- Counts root servers with incorrect IPs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsRootServerIncorrectDetails |
| Tags | AD, AD-DNS-04, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsRootServerIncorrectDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsRootServerIncorrectDetails.ps1

