Tuesday 24 February 2015

What does the _msdcs zone do?

This zone is present as a subdomain under each domain and advertises all of the different services available - such as LDAP and kerboros.

There is also a several other subdomains:

dc: Used by clients to identify which domain contoller(s) it should use.
pdc: Used to identify the primary domain controller of the domain.

There is also a _msdcs zone in the root forest domain - although there are a few differences:

- All DC's in the entire forest register a CNAME record here (required for replication)
- There is a GC subdomain that lists all of the global catalog servers.
- There is a domains subdomain that lists all of the domains along with their GUID's.


