Skip to main content
Version: 2.2.1-preview

AD-DNS-08 - Zone delegation count should be retrievable

Overviewโ€‹

DNS zone delegations transfer authority for a subdomain to different name servers. Monitoring delegations is important because:

  • Security boundaries: Delegations may cross administrative or security boundaries
  • External dependencies: Delegations may point to external/untrusted servers
  • Configuration complexity: Each delegation adds management overhead
  • Potential hijacking: Unauthorized delegations could redirect traffic

Security Recommendationโ€‹

  • Audit all zone delegations regularly
  • Verify delegated servers are under your organization's control
  • Document the purpose of each delegation
  • Monitor for unauthorized delegation changes

How the Test Worksโ€‹

This test counts NS records that represent delegations (where the record name is not "@"), indicating authority delegation to another server.

  • Test-MtAdDnsZoneDelegationDetails - Provides detailed delegation information

Test Metadataโ€‹

FieldValue
Test IDAD-DNS-08
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsZoneDelegationCount
TagsAD, AD-DNS-08, AD.DNS

Sourceโ€‹

  • Pester test: tests/ad/dns/Test-MtAdDnsZoneDelegationCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsZoneDelegationCount.ps1