Server 2019 domain controller issue

Srinivas M 121 Reputation points
2020-08-12T18:38:51.517+00:00

Hi

We have newly promoted server 2019 as a domain controller. post successful configuration we are getting a file by name: DNS settings and Type:msDNS-ServerSettings

17225-image.png

I have never seen this earlier. please clarify what is this file and is it by design or do we need to delete it or is it safe to ignore it.

Thanks
Sunny

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,228 questions
0 comments No comments
{count} votes

Accepted answer
  1. Shashi Shailaj 7,606 Reputation points Microsoft Employee
    2020-08-12T19:12:06.9+00:00

    Hello @Srinivas M ,

    The msDNS-ServerSettings contains the settings for the DNS service and information about all the AD integrated DNS zones which this particular server is the Key Master. It contains the LDAP location for all the Key master zones within AD database as you can see below. The Attribute msDNS-KeymasterZones contains the list of AD integrated DNS zones. You should not delete it . It was introduced in windows 2012 and is used if you have implemented DNSSEC feature in your environment for secure DNS. There is a concept of Key Master role and this attribute is queries to specifically find about the server holsing the key master role in case of DNSSEC . Its a big topic in itself , you can read more in the linked article or deploy a test lab for the same to understand more.

    17180-image.png

    This is by design and its safe to ignore. I would not recommend to remove it or modify it unless Microsoft Support asks you while troubleshooting any issue or you understand the implications. Hope this clarifies your query. If the information provided is helpful please do accept this as answer so that its helpful for other members of the community searching for similar answers.

    Thank you.

    0 comments No comments

3 additional answers

Sort by: Newest
  1. Bud Spencer 21 Reputation points
    2021-04-01T08:26:24.567+00:00

    Can this file be deleted of dc has been demoted?


  2. 2020-08-13T02:57:16.103+00:00

    Just to check if the above reply could be of help, if yes, you may mark useful reply as answer, if not, welcome to feedback.

    Best regards,
    Sylvia

    0 comments No comments

  3. Anonymous
    2020-08-12T19:11:49.98+00:00

    Looks like this one may be a key master, nothing to worry about.
    https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dnsp/24e513b0-0b67-4cbe-b149-f287f3acf6fd

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.