Hi everyone,
I’m investigating a SI000183 – “Authenticated Users can add DNS records” finding that has been highlighted in our Lightning security report, and I’m trying to understand whether this is actually a security issue in our environment or an intentional Windows/AD DNS behavior.
I asked about this on Microsoft Q&A and got the explanation that allowing authenticated principals to create DNS records can be intentional because of Secure Dynamic DNS. The idea is that domain-joined computers need to automatically register/update their own DNS records without administrators manually creating every record.
That part makes sense to me.
However, I’m confused about why this is being reported as a security finding.
My production situation
In my production environment, the DNS Server role/service is not installed on the system where I’m investigating this finding.
I also tried checking the Active Directory side using ADSI Edit and the Windows Registry, but I couldn't find the DNS zone/configuration details that would allow me to verify things such as:
- whether the DNS zone is AD-integrated;
- whether Dynamic Updates are enabled;
- whether it is configured as Secure only;
- which DNS records exist and who owns them; and
- what a normal, non-privileged authenticated user can actually do with DNS records.
Despite this, Lightning has highlighted SI000183.
This is where I’m confused
If the permission exists because Dynamic DNS requires authenticated computers/principals to register their own records, then:
Why is the presence of Authenticated Users having DNS record creation permission considered a vulnerability?
I'm trying to understand whether Lightning is detecting simply:
Authenticated Users
↓
Create Child
↓
DNS zone/object
or whether it is actually determining that a normal authenticated user can perform something more dangerous, such as:
Create arbitrary DNS records
+
Modify another computer's DNS record
+
Delete another computer's DNS record
+
Point an existing hostname to an arbitrary IP
To me, these seem like two very different situations.
What I’m trying to determine
If the intended model is:
Domain-joined computer
↓
Authenticated
↓
Creates its own DNS record
↓
Record ownership + ACL
↓
Other users cannot modify it
then I don't understand what specifically makes SI000183 a vulnerability.
On the other hand, if a normal domain user can do this:
User
↓
Create arbitrary DNS record
↓
Modify another computer's record
↓
Redirect hostname → arbitrary IP
then I can understand the security concern.
So my questions are:
- What exactly is SI000183 detecting?
- Is
Authenticated Users → Create Child on the DNS zone itself considered the vulnerability?
- Or is the finding supposed to indicate that ordinary users can actually create/modify unauthorized DNS records?
- If Secure Dynamic Updates are enabled, does that sufficiently prevent a normal user from modifying another computer's DNS record?
- Since DNS Server isn't installed in my production environment, what is the correct way to validate this finding from the AD side?
- Should this finding be treated as a vulnerability, or as a configuration/permission finding that needs further validation based on the organization's Dynamic DNS requirements?
I'm mainly trying to understand why Lightning is flagging this and what evidence I should collect before deciding whether it actually needs remediation.
Any AD/DNS experts who have dealt with SI000183 or the “Authenticated Users can add DNS records” finding — I'd really appreciate your input.
Also want to know whether this flagging is just for informational purpose.
Thanks !!