STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The DNS server implementation must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.

DISA Rule

SV-259411r961062_rule

Vulnerability Number

V-259411

Group Title

SRG-APP-000185-DNS-000021

Rule Version

WDNS-22-000092

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS system to use multifactor authentication for nonlocal access for maintenance and diagnostics.

Check Contents

Review the DNS implementation's authentication methods and settings to determine if multifactor authentication is used to gain nonlocal access for maintenance and diagnostics.

If multifactor authentication is not used, this is a finding.

Vulnerability Number

V-259411

Documentable

False

Rule Version

WDNS-22-000092

Severity Override Guidance

Review the DNS implementation's authentication methods and settings to determine if multifactor authentication is used to gain nonlocal access for maintenance and diagnostics.

If multifactor authentication is not used, this is a finding.

Check Content Reference

M

Target Key

5576