Strange DNS queries searching for aatp.dns.detection.local being made from MSDI sensors on DCs

Copper Contributor

We have noticed that DNS queries for aatp.dns.detection.local are coming from MSDI sensors on some of our DCs. The strange thing is that the queries are going to DNS servers that are not configured anywhere on the DC or elsewhere. The DNS servers that the queries are directed to are going to be switched off in the near future - will this cause an issue for MSDI detections?

1 Reply

@tonywvincent this us by design.

Thise server most likely issued axfr to ine if the sensor machines. In reponse the sensor tries to do various tests to learn if this is a real dns server... One the machine is gone it wont try to conect it any more, so no issues.