STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Windows DNS Server must restrict incoming dynamic update requests to known clients.

DISA Rule

SV-259334r960735_rule

Vulnerability Number

V-259334

Group Title

SRG-APP-000001-DNS-000115

Rule Version

WDNS-22-000001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Once selected, right-click the name of the zone.

From the displayed context menu, click the "Properties" option.

On the opened domain's properties box, click the "General" tab.

If the "Type:" is not "Active Directory-Integrated", configure the zone for Active Directory integration.

Select "Secure only" from the "Dynamic updates:" drop-down list.

Check Contents

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Once selected, right-click the name of the zone.

From the displayed context menu, click the "Properties" option.

On the opened domain's properties box, click the "General" tab.

Verify the "Type:" is "Active Directory-Integrated".

Verify "Dynamic updates" has "Secure only" selected.

If the zone is "Active Directory-Integrated" and "Dynamic updates" are not configured for "Secure only", this is a finding.

Vulnerability Number

V-259334

Documentable

False

Rule Version

WDNS-22-000001

Severity Override Guidance

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Once selected, right-click the name of the zone.

From the displayed context menu, click the "Properties" option.

On the opened domain's properties box, click the "General" tab.

Verify the "Type:" is "Active Directory-Integrated".

Verify "Dynamic updates" has "Secure only" selected.

If the zone is "Active Directory-Integrated" and "Dynamic updates" are not configured for "Secure only", this is a finding.

Check Content Reference

M

Target Key

5576