18.5.4.2 Ensure 'Turn off multicast name resolution' is set to 'Enabled'

Information

This policy setting determines whether to require domain users to elevate when setting a network's location.

The recommended state for this setting is: 'Enabled'.

Rationale:
Allowing regular users to set a network location increases the risk and attack surface.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':

Computer Configuration\Policies\Administrative Templates\Network\DNS Client\Turn off multicast name resolution

Note: This Group Policy path may not exist by default.

It is provided by the Group Policy template 'DnsClient.admx/adml' that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:

In the event DNS is unavailable a system will be unable to request it from other systems on the same subnet.

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: bbdd5071e25adb6eeb8b928ee7c8592d1d4574c1eb581a6cb2865e9874069ba3