Network, logging and monitoring

Are protective DNS or DNS filtering services in use?

DNS filtering is one of the cheapest controls that interrupts a real intrusion, because almost everything malicious resolves a name first.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether name resolution is filtered against malicious and newly registered domains, blocking the lookup before a connection is made. It covers both user browsing and machine-to-machine traffic.

Why it is underwritten

Phishing links, malware downloads, and command and control channels overwhelmingly use domain names. Blocking resolution stops the connection early, works regardless of the application making it, and produces high-quality telemetry. Carriers treat it as an inexpensive control with meaningful effect.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Where DNS filtering is a third-party service it is attested. Azure provides DNS-layer threat detection that is measurable.

PlatformWhere the setting livesWhat has to be true
DNS serviceProtective DNS provider and enabled categoriesMalicious, newly registered, and uncategorised domains blocked. Attested
AzureDefender for DNSEnabled, which detects malicious resolution from Azure resources including data exfiltration over DNS
NetworkWhether clients can bypass the filtering resolverOutbound DNS to arbitrary resolvers blocked, since a device using a public resolver skips the control entirely
EndpointEncrypted DNS settings in browsers and the operating systemDNS over HTTPS in browsers can bypass network filtering unless managed by policy
CoverageWhether remote devices are coveredRoaming clients covered by an agent, since network-based filtering protects only devices on the network
Encrypted DNS bypasses network filtering

Browsers can resolve names over HTTPS to their own resolver, which walks straight past a filtering DNS server. Unless browser policy disables it or points it at your resolver, your DNS filtering covers less than you think.

What a defensible yes requires

  • Filtering covers malicious, newly registered, and uncategorised domains.
  • Devices cannot use alternative resolvers, including encrypted DNS in browsers.
  • Remote devices are covered off the corporate network.
  • Server and machine traffic is covered as well as user browsing.
  • Blocked queries are logged and reviewed, since they are high-quality intrusion indicators.

How this answer goes wrong

Filtering is deployed on the corporate network and the workforce is largely remote, so the control applies to a fraction of the fleet. Or it is deployed everywhere and browsers use encrypted DNS by default, bypassing it silently.

Frequently asked

Is this the same as web filtering?

Related and distinct. DNS filtering blocks at resolution and covers all protocols; web filtering inspects HTTP traffic and can be more granular. They complement each other and carriers ask about both.

Does it stop ransomware?

It interrupts common stages: the download, the command and control channel, and sometimes exfiltration. It is a layer, not a guarantee.

What about newly registered domains?

Blocking them is one of the highest-value categories, because phishing infrastructure is usually days old. Expect a small number of false positives and an exception path.

Do we need a paid service?

The category is inexpensive and several capable options exist. The cost is rarely the obstacle; coverage of remote devices usually is.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture