Skip to main content
Version: 2.2.1-preview

AD-DNS-19 - Reverse zone network details should be retrievable

Overviewโ€‹

Detailed information about networks with reverse lookup zones enables:

  • Network inventory: Complete list of networks with reverse DNS
  • Security auditing: Verification that only authorized networks are configured
  • Troubleshooting: Quick identification of reverse DNS coverage
  • Documentation: Accurate records of DNS infrastructure

Understanding which networks have reverse zones is essential for comprehensive DNS management.

Security Recommendationโ€‹

Review reverse zone network details regularly:

  • Verify all listed networks are authorized
  • Ensure CIDR notation is appropriate for each network
  • Document the purpose of each reverse zone
  • Remove reverse zones for decommissioned networks

How the Test Worksโ€‹

This test provides detailed information about each network with a reverse lookup zone, including:

  • Network address
  • CIDR notation
  • Reverse zone name
  • Zone type
  • Test-MtAdDnsReverseZoneCount - Counts reverse lookup zones
  • Test-MtAdDnsReverseZoneNetworkCount - Counts distinct networks

Test Metadataโ€‹

FieldValue
Test IDAD-DNS-19
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsReverseZoneNetworkDetails
TagsAD, AD-DNS-19, AD.DNS

Sourceโ€‹

  • Pester test: tests/ad/dns/Test-MtAdDnsReverseZoneNetworkDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsReverseZoneNetworkDetails.ps1