hpshelton / hpshelton.github.io

Blog content for hpshelton.com
http://hpshelton.com/
2 stars 0 forks source link

Announcing Zero Trust DNS Private Preview - Microsoft Community Hub #142

Closed hpshelton closed 2 months ago

hpshelton commented 6 months ago

layout: post type: link date: 2024-08-26 18:00:00 -0700 title: "Announcing Zero Trust DNS Private Preview" link: https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366 permalink: /post/2024/05/07/zero-trust-dns categories:

hpshelton commented 6 months ago

Admins are left to choose between equally unappealing options: (1) route DNS traffic in clear text with no means for the server and client device to authenticate each other so malicious domains can be blocked and network monitoring is possible, or (2) encrypt and authenticate DNS traffic and do away with the domain control and network visibility.

ZTDNS aims to solve this decades-old problem by integrating the Windows DNS engine with the Windows Filtering Platform—the core component of the Windows Firewall—directly into client devices.

Jake Williams, VP of research and development at consultancy Hunter Strategy, said the union of these previously disparate engines would allow updates to be made to the Windows firewall on a per-domain name basis. The result, he said, is a mechanism that allows organizations to, in essence, tell clients “only use our DNS server, that uses TLS, and will only resolve certain domains.” Microsoft calls this DNS server or servers the “protective DNS server.”

https://arstechnica.com/security/2024/05/microsoft-plans-to-lock-down-windows-dns-like-never-before-heres-how/

hpshelton commented 2 months ago

psot

hpshelton commented 2 months ago

post

hpshelton commented 2 months ago

https://github.com/hpshelton/hpshelton.github.io/commit/d51c1043d7b4a95c0ccd2b2e8c183a3340cd2eb8

hpshelton commented 2 months ago

Posted by https://github.com/hpshelton/hpshelton.github.io/actions/runs/10570414438
http://hpshelton.com/post/2024/08/26/zero-trust-dns