Skip to main content
Version: 2.2.1-preview

AD-DNS-13 - DNSSEC record count should be retrievable

Overviewโ€‹

DNSSEC (DNS Security Extensions) provides authentication of DNS data through digital signatures. Trust anchors are the starting points for DNSSEC validation:

  • Data integrity: DNSSEC prevents DNS spoofing and cache poisoning
  • Authentication: Clients can verify DNS responses are authentic
  • Compliance: Some regulations require DNSSEC deployment
  • Trust establishment: Trust anchors enable validation chains

Security Recommendationโ€‹

  • Deploy DNSSEC for all externally-facing DNS zones
  • Maintain secure trust anchor distribution
  • Monitor for DNSSEC validation failures
  • Keep DNSSEC keys properly managed and rotated

How the Test Worksโ€‹

This test counts DNSSEC trust anchor records configured in the TrustAnchors zone.

  • None currently

Test Metadataโ€‹

FieldValue
Test IDAD-DNS-13
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsDnssecRecordCount
TagsAD, AD-DNS-13, AD.DNS

Sourceโ€‹

  • Pester test: tests/ad/dns/Test-MtAdDnsDnssecRecordCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsDnssecRecordCount.ps1