Question about secure and unsecure DNS registration

Jeroen Bleeker 41 Reputation points
2021-03-10T13:23:13.787+00:00

Hi

In Windows DNS servers you can configure a DNS zone with one of these options:

  • secure
  • nonsecure and secure
  • none

When you choose "nonsecure and secure" -> when you want a secure registration as a client, how can you force that (i think it is impossible and that you can't use a secure registration when you use this option) .

Regards, Jeroen BLeeker

Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,021 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sunny Qi 10,896 Reputation points Microsoft Vendor
    2021-03-11T05:49:34.847+00:00

    Hi,

    Thanks for posting in Q&A platform.

    I'm afraid your goal cannot be achieved. By default, dynamic update security for DNS servers and clients are handled as this: DNS clients attempt to use unsecured dynamic update first. If an unsecured update is update successfully, the client will no longer request a secure update. If an unsecured update is refused, clients try to use secure update. DNS update security is available only for zones that are integrated into Active Directory.

    Unsecured dynamic update allows anyone on your network to register DNS records with no Active Directory authentication required.

    So, normally, we recommend configure Dynamic updates as Secure only.

    For more details regarding DNS dynamic update, please refer to the following article:

    Understanding Dynamic Update

    Best Regards,
    Sunny

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Jeroen Bleeker 41 Reputation points
    2021-03-11T07:36:13.877+00:00

    Hi Sunny,

    Thanx for your response. I think Microsoft should have called it 'nonsecure' and not 'nonsecure and secure', it's misleading.

    Regards, Jeroen Bleeker