STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

Primary authoritative name servers must be configured to only receive zone transfer requests from specified secondary name servers.

DISA Rule

SV-259354r961863_rule

Vulnerability Number

V-259354

Group Title

SRG-APP-000516-DNS-000095

Rule Version

WDNS-22-000024

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Right-click the zone and select "Properties".

Select the "Zone Transfers" tab.

Select the "Only to servers listed on the Name Server tab" or "Only to the following servers" check box or deselect the "Allow zone transfers" check box.

Click "OK".

Check Contents

Determine if the authoritative primary name server is Active Directory (AD) integrated.

Determine if all secondary name servers for every zone for which the primary name server is authoritative are AD-integrated in the same Active Directory.

If the authoritative primary name server is AD integrated and all secondary name servers are part of the same AD, this check is not a finding because AD handles the replication of DNS data.

If one or more of the secondary name servers are non-AD integrated, verify the primary name server is configured to only send zone transfers to a specific list of secondary name servers.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Right-click the zone and select "Properties".

Select the "Zone Transfers" tab.

If the "Allow zone transfers:" check box is not selected, this is not a finding.

If the "Allow zone transfers:" check box is selected, verify either "Only to servers listed on the Name Server tab" or "Only to the following servers" is selected.

If the "To any server" option is selected, this is a finding.

Vulnerability Number

V-259354

Documentable

False

Rule Version

WDNS-22-000024

Severity Override Guidance

Determine if the authoritative primary name server is Active Directory (AD) integrated.

Determine if all secondary name servers for every zone for which the primary name server is authoritative are AD-integrated in the same Active Directory.

If the authoritative primary name server is AD integrated and all secondary name servers are part of the same AD, this check is not a finding because AD handles the replication of DNS data.

If one or more of the secondary name servers are non-AD integrated, verify the primary name server is configured to only send zone transfers to a specific list of secondary name servers.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press the Windows key + R and execute "dnsmgmt.msc".

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand "Forward Lookup Zones".

From the expanded list, click to select the zone.

Right-click the zone and select "Properties".

Select the "Zone Transfers" tab.

If the "Allow zone transfers:" check box is not selected, this is not a finding.

If the "Allow zone transfers:" check box is selected, verify either "Only to servers listed on the Name Server tab" or "Only to the following servers" is selected.

If the "To any server" option is selected, this is a finding.

Check Content Reference

M

Target Key

5576