Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to monitor deletions of DNS records

DNS servers are crucial for the operation of any network. DNS records allow DNS servers to map name requests to corresponding IP addresses. Modification or deletion of DNS records can result in service unavailability. Hence, it is crucial to monitor DNS record modification to accelerate forensic analysis in case of a mishap.

Download for Free
Free, fully functional 30-day trial
  • With Native AD Auditing

  • With ADAudit Plus

  • How to detect deletion of DNS records with ADAudit Plus
  • Once ADAudit Plus has been installed, it automatically configures audit policies required for Active Directory auditing.

    To enable automatic configuration: Log in to the ADAudit Plus web console → Domain Settings → Audit Policy: Configure.

    Deletions in DNS records can be identified by following the below mentioned steps:

  • Login to ADAudit Plus.

  • Select the required Domain from the dropdown list.

  • Go to theReports tab.

  • Navigate to DNS Changes.

  • Select DNS Nodes Removed.

  • how-to-monitor-deletions-of-dns-records-5
  • [Highlight reports, domain, DNS changes,DNS Nodes removed]

  • how-to-monitor-deletions-of-dns-records-6

ADAudit Plus enables IT administrators to have a comprehensive picture of all the activities that happen within their organization's network. The real-time monitoring and out-of-the-box reports offered by ADAudit Plus makes it easier to track critical changes in DNS records, and detect and prevent mishaps.

With native AD auditing, here is how you can monitor the DNS record deletion:

  • Step 1: Enable 'Audit logon events' policy
  • LaunchServer Manager in your Windows Server instance.

  • Under Manage, select Group Policy Management and launch the Group Policy Management console.

  • Navigate to Forest --> Domain --> Your domain --> Domain Controllers.

  • Create a new GPO and link it to the domain containing the computer object, or edit any existing GPO that is linked to the domain to open the Group Policy Management Editor.

  • Navigate to Computer Configuration ➔ Windows Settings ➔ Security Settings ➔ Local Policy ➔ Audit Policy

  • Under Audit Policy turn auditing on for Success of Audit Directory Service Access policy.

  • how-to-monitor-deletions-of-dns-records-1
  • Step 2: Allow AD Auditing through ADSI Edit
  • From your Server Manager go to Tools and select ADSI Edit.

  • Right-click ADSI Edit node from the left pane and select Connect to option. This pulls up the Connection Settings window.

  • Select the Default Naming Context option from the Select a well known Naming Context drop down list.

  • how-to-monitor-deletions-of-dns-records-2
  • Click OK and return to the ADSI Edit window. Expand Default Naming Context and select the associated DC subnode. Right-click this subnode, and click Properties.

  • In theProperties window, go to the Securitytab and select Advanced. After that select Auditing tab and click Add.

  • Apply the following settings

    1. Principal: Everyone
    2. Type: Success
    3. Applies to: This object and all descendant objects
    4. Permissions: Select Write all properties, Delete, Delete subtree check boxes.
  • Click Apply, then OK, and close the console.

  • Step 3: Enable Auditing through DNS Manager
  • From your Server Manager go to Tools and select DNS.

    how-to-monitor-deletions-of-dns-records-3
  • Expand your servername and select Forward Lookup Zone.

  • Right-click the zone you want to audit, and click on Properties.

  • In the Properties window, go to the Security tab and select Advanced. After that select Auditing tab, and click Add.

  • Apply the following settings

    1. Principal: Everyone
    2. Type: Success
    3. Applies to: This object and all descendant objects
    4. Permissions: Select Write all properties, Delete, Delete subtree check boxes.
  • Click Apply, then OK, and close the console.

  • Step 4: View events in Event Viewer
  • In Event Viewer window, go to Windows Logs ➔ Security logs.

  • Click on Filter current log under Action in the right panel.

  • Search for Event ID 4662 that identifies DNS record changes.

  • You can double-click on the event to view Event Properties. how-to-monitor-deletions-of-dns-records-4
  • These steps need to be repeated for all the zones to audit changes in DNS records. Manually checking every event is time-consuming, inefficient and practically impossible for large organizations.

Native auditing becoming a little too much?

Simplify DNS record auditing and reporting with ADAudit Plus.

Get Your Free Trial Fully functional 30-day trial

ADAudit Plus simplifies DNS record history tracking by offering several predefined DNS Changes reports along with intuitive graphical representation of the same for ease of comprehension. ADAudit Plus also provides the option to generate custom reports and export them in your preferred format PDF, XLS, HTML, and CSV.

Request 1-on-1 demo

  •  
  •  
  •  
  •  
  •  
  • -Select-
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.

Thanks

One of our solution experts will get in touch with you shortly.

ADAudit Plus Trusted By