Skip to main content
Version: 2.2.1-preview

AD-DNS-11 - AD DS SRV record count should be retrievable

Overview​

SRV records are essential for Active Directory service location. They enable clients to find:

  • Domain controllers (_ldap records)
  • Global Catalog servers (_gc records)
  • Kerberos services (_kerberos records)
  • Password change services (_kpasswd records)

Missing or incorrect SRV records can prevent:

  • Domain join operations
  • Authentication
  • Group Policy application
  • Service discovery

Security Recommendation​

  • Monitor SRV record counts for unexpected changes
  • Verify SRV records point to authorized domain controllers only
  • Protect DNS zones containing SRV records from unauthorized modification
  • Regularly test service location from client perspectives

How the Test Works​

This test counts SRV records used by Active Directory Domain Services, including _ldap, _gc, _kerberos, and _kpasswd service records.

  • Test-MtAdDnsAdSrvRecordDetails - Provides detailed SRV record information

Test Metadata​

FieldValue
Test IDAD-DNS-11
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsAdSrvRecordCount
TagsAD, AD-DNS-11, AD.DNS

Source​

  • Pester test: tests/ad/dns/Test-MtAdDnsAdSrvRecordCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsAdSrvRecordCount.ps1