AD-DNS-14 - Empty zone count should be retrievable
Overviewβ
Empty DNS zones (zones with no resource records) may indicate:
- Incomplete configuration: Zones created but never populated
- Abandoned infrastructure: Services that were planned but never deployed
- Configuration errors: Failed zone creation or replication issues
- Cleanup opportunities: Removing unused zones reduces complexity
Empty zones add administrative overhead without providing value and may confuse administrators.
Security Recommendationβ
- Audit empty zones regularly
- Delete zones that are no longer needed
- Document the purpose of any intentionally empty zones
- Investigate unexpected empty zones for potential issues
How the Test Worksβ
This test identifies DNS zones that contain zero resource records of any type.
Related Testsβ
Test-MtAdDnsZoneCount- Counts zones with recordsTest-MtAdDnsZonesWithOnlySoaNs- Finds zones with only default records
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-14 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsEmptyZoneCount |
| Tags | AD, AD-DNS-14, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsEmptyZoneCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsEmptyZoneCount.ps1

