disabling DNS updated for all member servers - consequences

AdamJozwicki-7216 1 Reputation point
2022-08-04T12:07:02.71+00:00

Hi,
I fed up with dynamic DNS records created by member servers and issues caused by the fact that server owner completely do not understand it and screams when such DNS record is scavenged, not sure about the reason. Neverheless, I would like to disable it for all servers using static IP address configuration.
I can do it in GPO "Dynamic update" = disabled (https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.DNSClient::DNS_RegistrationEnabled)
Before that I can find and convert all existing dynamic records to static to avoid DNS Scavending.
My question: what can I break? :) especially I'm thinking of Windows clusters.

what I know from https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/enable-disable-dns-dynamic-registration
is that there are 2 services responsible for DNS registration:
DHCP Client for all Windows (A and PTR)
Netlogon for Domain controllers only - I do not plan to disable it of course. My DNS servers run on DC server, there is no standalone DNS.

My GPO will be applied only on member servers.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,912 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,023 questions
Windows Server Clustering
Windows Server Clustering
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Clustering: The grouping of multiple servers in a way that allows them to appear to be a single unit to client computers on a network. Clustering is a means of increasing network capacity, providing live backup in case one of the servers fails, and improving data security.
960 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Gary Reynolds 9,391 Reputation points
    2022-08-04T12:31:30.51+00:00

    In the DNS console for each records that you want to change to static, open the properties and uncheck the Delete this record when it becomes stale and the record will be converted into a static record.

    228155-image.png

    From the brief testing I've completed the record doesn't get changed back to dynamic.

    Gary

    0 comments No comments

  2. AdamJozwicki-7216 1 Reputation point
    2022-08-04T12:35:06.687+00:00

    That one I know. My question was if there any any Windows related mechanism like cluster service which may suffer from disabling Dynamic updates (even if I convert all records to static before).


  3. Limitless Technology 39,386 Reputation points
    2022-08-05T15:51:31.407+00:00

    Hi there,

    Clearing the DNS server will remove any invalid addresses, whether because they're outdated or because they've been manipulated. It's also important to note flushing the cache doesn't have any negative side effects.

    Below are the services that are responsible for Host A record registration on a DC:

    -Netlogon service
    -DNS server service (if the DC is running DNS server service)
    -DHCP client or DNS client (2003/2008)

    ---------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–

    0 comments No comments