Automated Site Coverage by the DC Locator DNS SRV RecordsID: oval:org.secpod.oval:def:19314 | Date: (C)2014-05-29 (M)2023-07-04 |
Class: COMPLIANCE | Family: windows |
The Automated Site Coverage by the DC Locator DNS SRV Records machine setting should be configured correctly.
Determines whether domain controllers (DC) will dynamically register DC Locator site-specific SRV records for the closest sites where no DC for the same domain exists (or no Global Catalog for the same forest exists). These DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC. If this setting is enabled, the DCs to which this setting is applied dynamically register DC Locator site-specific DNS SRV records for the closest sites where no DC for the same domain, or no Global Catalog for the same forest, exists. If you disable this setting, the DCs will not register site-specific DC Locator DNS SRV records for any other sites but their own. If this setting is not configured, it is not applied to any DCs, and DCs use their local configuration.
Fix:
(1) GPO: Computer Configuration\Administrative Templates\System\Net Logon\DC Locator DNS Records\Automated Site Coverage by the DC Locator DNS SRV Records
(2) KEY: HKLM\Software\Policies\Microsoft\Netlogon\Parameters\AutoSiteCoverage
Platform: |
Microsoft Windows Server 2008 R2 |