May 07 2024 08:55 AM
We have noticed that DNS queries for aatp.dns.detection.local are coming from MSDI sensors on some of our DCs. The strange thing is that the queries are going to DNS servers that are not configured anywhere on the DC or elsewhere. The DNS servers that the queries are directed to are going to be switched off in the near future - will this cause an issue for MSDI detections?
May 07 2024 02:44 PM
@tonywvincent this us by design.
Thise server most likely issued axfr to ine if the sensor machines. In reponse the sensor tries to do various tests to learn if this is a real dns server... One the machine is gone it wont try to conect it any more, so no issues.