Danger of Scavenging Stale Resource Records In _msdcs Zone?
I just realized that a previous admin turned DNS scavenging on for all zones on one of the DCs, including the _msdcs zone. It’s been this way for a while and things are fine, but I can’t imagine that this is best practice. Is there any danger to scavenging the _msdcs zone? Should I make it so that zone is not scavenged? Could scavenging have broken anything in that zone that I’m unaware of at [...]
Continue Reading »Does _msdcs needs to have Zone Transfer enabled with 2 domain controllers
I have _msdcs Active Directory Integrated. Do I need to enable Zone transfers and notifications on changes? I have 2 domain controllers with DNS/DHCP enabled on them? I would think yes, but it’s disabled and I am not sure why? Windows 2008 R2 controllers were migrated from Windows 2003. It should replicate using AD replication, therefore zone transfer settings should be irrelevant. Do you have any DNS and/or AD replication issues? Check more discussion of [...]
Continue Reading »How can I identify the current domain from these dns entries under domains._msdcs tree?
I hope everybody had a good July 4th! Looking through my DNS entries, I see the following: My questions are: How do I identify which of these belongs to the current domain? Is it safe to delete the rest of them or should I just leave them all alone? Is there any harm done in keeping them? How are these ids generated? The reason I’m asking these is because I have had to rebuild Active [...]
Continue Reading »Recent Posts
- Understanding redundant power supplies
- Is there a way for administrators to disable users from installing Firefox extensions?
- Is there research material on NTP accuracy available?
- How to create a limited “domain admin” that does not have access to domain controllers?
- Can Windows RDC admin users be immune from being kicked?



