Not only is DNS important in our corporate network, it is also an important service for many systems on the internet, so DNS, one of the most important services, is particularly critical to his audit. But the changes in DNS registration information rarely have audit software to record, and as a third party audit software is more or less the same as the Windows kernel is not fully compatible with the collaboration, then when we need to know the company domain DNS record change information, how to do?
In fact, we can also use the built-in audit function of Windows
On a domain controller: Audit directory service access
Audit directory service access:
Audit successful operations
Audit Failed actions
There are three kinds of DNS zone types: Primary, secondary, stub zone
To confirm DNS replication scope
In the illustration above, my DNS is installed at the domain level by default, so queries in ADSIEdit are used as follows: