AD-DNS-08 - Zone delegation count should be retrievable
Overviewโ
DNS zone delegations transfer authority for a subdomain to different name servers. Monitoring delegations is important because:
- Security boundaries: Delegations may cross administrative or security boundaries
- External dependencies: Delegations may point to external/untrusted servers
- Configuration complexity: Each delegation adds management overhead
- Potential hijacking: Unauthorized delegations could redirect traffic
Security Recommendationโ
- Audit all zone delegations regularly
- Verify delegated servers are under your organization's control
- Document the purpose of each delegation
- Monitor for unauthorized delegation changes
How the Test Worksโ
This test counts NS records that represent delegations (where the record name is not "@"), indicating authority delegation to another server.
Related Testsโ
Test-MtAdDnsZoneDelegationDetails- Provides detailed delegation information
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DNS-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsZoneDelegationCount |
| Tags | AD, AD-DNS-08, AD.DNS |
Sourceโ
- Pester test:
tests/ad/dns/Test-MtAdDnsZoneDelegationCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsZoneDelegationCount.ps1

