Skip to main content
Version: 2.2.1-preview

AD-DNS-07 - Zone record count details should be retrievable

Overview​

Detailed record distribution across zones helps identify:

  • High-traffic zones: Zones with many records may be critical infrastructure
  • Underutilized zones: Zones with few records may be candidates for consolidation
  • Potential issues: Unusual record distributions may indicate problems
  • Resource planning: Understanding record counts helps capacity planning

Security Recommendation​

Review zones with unusually high record counts for:

  • Stale or orphaned records that should be removed
  • Unauthorized records that may indicate compromise
  • Configuration errors causing excessive record creation

How the Test Works​

This test provides a detailed breakdown of record counts per zone, including the most common record types in each zone.

  • Test-MtAdDnsZoneCount - Counts zones with records
  • Test-MtAdDnsDynamicRecordCount - Analyzes dynamic vs static records

Test Metadata​

FieldValue
Test IDAD-DNS-07
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsZoneRecordDetails
TagsAD, AD-DNS-07, AD.DNS

Source​

  • Pester test: tests/ad/dns/Test-MtAdDnsZoneRecordDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsZoneRecordDetails.ps1