Skip to main content
Version: 2.2.1-preview

AD-DNS-14 - Empty zone count should be retrievable

Overview​

Empty DNS zones (zones with no resource records) may indicate:

  • Incomplete configuration: Zones created but never populated
  • Abandoned infrastructure: Services that were planned but never deployed
  • Configuration errors: Failed zone creation or replication issues
  • Cleanup opportunities: Removing unused zones reduces complexity

Empty zones add administrative overhead without providing value and may confuse administrators.

Security Recommendation​

  • Audit empty zones regularly
  • Delete zones that are no longer needed
  • Document the purpose of any intentionally empty zones
  • Investigate unexpected empty zones for potential issues

How the Test Works​

This test identifies DNS zones that contain zero resource records of any type.

  • Test-MtAdDnsZoneCount - Counts zones with records
  • Test-MtAdDnsZonesWithOnlySoaNs - Finds zones with only default records

Test Metadata​

FieldValue
Test IDAD-DNS-14
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsEmptyZoneCount
TagsAD, AD-DNS-14, AD.DNS

Source​

  • Pester test: tests/ad/dns/Test-MtAdDnsEmptyZoneCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsEmptyZoneCount.ps1