18.6.4.3 (L2) Ensure 'Turn off default IPv6 DNS Servers' is set to 'Enabled'

Information

This policy setting controls whether the DNS client will use the default IPv6 DNS server addresses provided by Windows.

The recommended state for this setting is: Enabled

Since the vast majority of private enterprise managed networks have no need to utilize IPv6 (because they have access to private IPv4 addressing), disabling the use of IPv6 DNS server addresses removes a possible attack surface that is also harder to monitor the traffic on.

It is not recommended to use DNS servers that are controlled by an external entity without input from the organization's IT department.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Network\DNS Client\Turn off default IPv6 DNS Servers

Note: This Group Policy path is provided by the Group Policy template DnsClient.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Default IPv6 DNS server addresses will not be utilized by Windows.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: d93c3120e3b9ad3a273a7e6a42a32c25412ad61466317b933132de58cc5a5d55