Information
This policy setting determines if the DNS client will perform name resolution over Multicast DNS (mDNS). mDNS performs local network name and service discoveries without the need for central DNS.
The recommended state for this setting is: Disabled
An attacker can listen on a network over UDP port 5353 and respond to them, tricking the host into thinking that it knows the location of the requested system.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled :
Computer Configuration\Policies\Administrative Templates\Network\DNS Client\Configure multicast DNS (mDNS) protocol
Note: This Group Policy path is provided by the Group Policy template DnsClient.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
In the event DNS is unavailable a system will be unable to request it from other systems on the same subnet.