2.20 Ensure 'Use built-in DNS client' is set to 'Disabled'

Information

Google Chrome offers to use a built-in DNS client.
Rationale:
The built-in DNS client shall not be used to circumvent the usage of a trusted DNS server.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Use built-in DNS client
Impact:
Users will not be able to use Google DNS-over-TLS and (in future) DNS-over-HTTPS if you disable the Chrome DNS stack.
Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-20, CSCv7|7.7

Plugin: Windows

Control ID: d87fdbc038aaaa32cd7eac581bc91761b7fea102cb8271b64bcc3e88b4790921