18.5.4.2 Ensure 'Turn off multicast name resolution' is set to 'Enabled'

Information

This policy setting determines whether to require domain users to elevate when setting a network's location.

The recommended state for this setting is: 'Enabled'.

Rationale:
Allowing regular users to set a network location increases the risk and attack surface.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':

Computer Configuration\Policies\Administrative Templates\Network\DNS Client\Turn off multicast name resolution

Note: This Group Policy path may not exist by default.

It is provided by the Group Policy template 'DnsClient.admx/adml' that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:

In the event DNS is unavailable a system will be unable to request it from other systems on the same subnet.

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 670f7540c95e836ce87ae628e4e61f9759fee8c0d6aff4a8683e65dbf5191852