{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
        "slug": "use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback",
        "url": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/"
        },
        "title": "Use Windows time-of-day DNS policies only with deterministic priority and fallback",
        "summary": "Use Use DNS Policy for Intelligent DNS Responses Based on the Time of Day to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:15:22+00:00",
        "modified_at": "2026-08-27T12:56:24+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 530,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Use DNS Policy for Intelligent DNS Responses Based on the Time of Day",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Use DNS Policy for Intelligent DNS Responses Based on the Time of Day",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent",
            "published_on": "2021-12-02",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to connect an official requirement or behavior to observable evidence: Use Windows time-of-day DNS policies only with deterministic priority and fallback. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent\" target=\"_blank\" rel=\"noopener noreferrer\">Use DNS Policy for Intelligent DNS Responses Based on the Time of Day</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>Windows DNS Policy can distribute application traffic according to time of day. The research record locates this support at <strong>Article introduction</strong>.</li>\n<li>Microsoft states that multiple DNS policies are ordered and that the first matching policy is used. The research record locates this support at <strong>Section &#8216;How Intelligent DNS Responses Based on Time of Day Works&#8217;</strong>.</li>\n</ul>\n<p>Keep the evidence boundary at these traced claims. They support a review of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles; they do not support conclusions outside the source&#8217;s stated conditions.</p>\n<h2>What the source does not establish</h2>\n<p>Time-based answers do not measure application health or client time zones, and the example values are not production recommendations. No current deployment state or change approval follows from the source alone. Validate Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution, and treat examples or options as conditional inputs rather than defaults.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Article introduction</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Section &#8216;How Intelligent DNS Responses Based on Time of Day Works&#8217;</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>What inventory proves which parts of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles are in and out of scope?</li>\n<li>Which condition in Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution must be healthy before evidence is trustworthy?</li>\n<li>What result would disprove the working assumption and return the issue to the owner?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles, observed and expected states, owner, and reason for deviation.</p>\n<p>Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution. Handle credentials, keys, recovery data, and personal information through approved secure channels.</p>\n<h2>Verification and evidence</h2>\n<p>A reviewer should be able to retrace the decision from <strong>Article introduction</strong>; <strong>Section &#8216;How Intelligent DNS Responses Based on Time of Day Works&#8217;</strong> through PowerShell exports, zone and policy inventories, sanitized query tests, event-channel data, replication state, and rollback commands. Record what was collected, where, when, by whom, and which system or role it represents.</p>\n<p>Preserve both successful and failed observations, along with approval and rollback evidence. Avoid uncontrolled production experiments. Assign an expiry or event-driven recheck so the conclusion is not treated as permanent.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent\" target=\"_blank\" rel=\"noopener noreferrer\">Use DNS Policy for Intelligent DNS Responses Based on the Time of Day</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to connect an official requirement or behavior to observable evidence: Use Windows time-of-day DNS policies only with deterministic priority and fallback. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Use DNS Policy for Intelligent DNS Responses Based on the Time of Day from Microsoft supports the following bounded statements:\n\nWindows DNS Policy can distribute application traffic according to time of day. The research record locates this support at Article introduction.\nMicrosoft states that multiple DNS policies are ordered and that the first matching policy is used. The research record locates this support at Section ‘How Intelligent DNS Responses Based on Time of Day Works’.\n\nKeep the evidence boundary at these traced claims. They support a review of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles; they do not support conclusions outside the source’s stated conditions.\nWhat the source does not establish\nTime-based answers do not measure application health or client time zones, and the example values are not production recommendations. No current deployment state or change approval follows from the source alone. Validate Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution, and treat examples or options as conditional inputs rather than defaults.\nApplicability questions\n\nFor source statement 1 at Article introduction, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Section ‘How Intelligent DNS Responses Based on Time of Day Works’, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles are in and out of scope?\nWhich condition in Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nA reviewer should be able to retrace the decision from Article introduction; Section ‘How Intelligent DNS Responses Based on Time of Day Works’ through PowerShell exports, zone and policy inventories, sanitized query tests, event-channel data, replication state, and rollback commands. Record what was collected, where, when, by whom, and which system or role it represents.\nPreserve both successful and failed observations, along with approval and rollback evidence. Avoid uncontrolled production experiments. Assign an expiry or event-driven recheck so the conclusion is not treated as permanent.\nOfficial references\n\nUse DNS Policy for Intelligent DNS Responses Based on the Time of Day — Microsoft",
        "content_markdown": "Use this document to connect an official requirement or behavior to observable evidence: Use Windows time-of-day DNS policies only with deterministic priority and fallback. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Use DNS Policy for Intelligent DNS Responses Based on the Time of Day](https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent) from Microsoft supports the following bounded statements:\n\n- Windows DNS Policy can distribute application traffic according to time of day. The research record locates this support at Article introduction.\n\n- Microsoft states that multiple DNS policies are ordered and that the first matching policy is used. The research record locates this support at Section ‘How Intelligent DNS Responses Based on Time of Day Works’.\n\nKeep the evidence boundary at these traced claims. They support a review of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles; they do not support conclusions outside the source’s stated conditions.\n\n## What the source does not establish\n\nTime-based answers do not measure application health or client time zones, and the example values are not production recommendations. No current deployment state or change approval follows from the source alone. Validate Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution, and treat examples or options as conditional inputs rather than defaults.\n\n## Applicability questions\n\n- For source statement 1 at Article introduction, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Section ‘How Intelligent DNS Responses Based on Time of Day Works’, which observable configuration, record, or test can confirm applicability here?\n\n- What inventory proves which parts of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles are in and out of scope?\n\n- Which condition in Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution must be healthy before evidence is trustworthy?\n\n- What result would disprove the working assumption and return the issue to the owner?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles, observed and expected states, owner, and reason for deviation.\n\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution. Handle credentials, keys, recovery data, and personal information through approved secure channels.\n\n## Verification and evidence\n\nA reviewer should be able to retrace the decision from Article introduction; Section ‘How Intelligent DNS Responses Based on Time of Day Works’ through PowerShell exports, zone and policy inventories, sanitized query tests, event-channel data, replication state, and rollback commands. Record what was collected, where, when, by whom, and which system or role it represents.\n\nPreserve both successful and failed observations, along with approval and rollback evidence. Avoid uncontrolled production experiments. Assign an expiry or event-driven recheck so the conclusion is not treated as permanent.\n\n## Official references\n\n- [Use DNS Policy for Intelligent DNS Responses Based on the Time of Day](https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
                "url": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Use Windows time-of-day DNS policies only with deterministic priority and fallback",
                        "item": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/#article",
                "identifier": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
                "url": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/",
                "headline": "Use Windows time-of-day DNS policies only with deterministic priority and fallback",
                "description": "Use Use DNS Policy for Intelligent DNS Responses Based on the Time of Day to review this narrow operational decision without extending the source…",
                "abstract": "Use Use DNS Policy for Intelligent DNS Responses Based on the Time of Day to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to connect an official requirement or behavior to observable evidence: Use Windows time-of-day DNS policies only with deterministic priority and fallback. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Use DNS Policy for Intelligent DNS Responses Based on the Time of Day from Microsoft supports the following bounded statements:\n\nWindows DNS Policy can distribute application traffic according to time of day. The research record locates this support at Article introduction.\nMicrosoft states that multiple DNS policies are ordered and that the first matching policy is used. The research record locates this support at Section ‘How Intelligent DNS Responses Based on Time of Day Works’.\n\nKeep the evidence boundary at these traced claims. They support a review of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles; they do not support conclusions outside the source’s stated conditions.\nWhat the source does not establish\nTime-based answers do not measure application health or client time zones, and the example values are not production recommendations. No current deployment state or change approval follows from the source alone. Validate Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution, and treat examples or options as conditional inputs rather than defaults.\nApplicability questions\n\nFor source statement 1 at Article introduction, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Section ‘How Intelligent DNS Responses Based on Time of Day Works’, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles are in and out of scope?\nWhich condition in Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of Windows DNS servers, AD-integrated zones, policies, forwarders, logging channels, clients, and administrative roles, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory replication, domain-controller health, service accounts, routing, time, certificates, and upstream resolution. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nA reviewer should be able to retrace the decision from Article introduction; Section ‘How Intelligent DNS Responses Based on Time of Day Works’ through PowerShell exports, zone and policy inventories, sanitized query tests, event-channel data, replication state, and rollback commands. Record what was collected, where, when, by whom, and which system or role it represents.\nPreserve both successful and failed observations, along with approval and rollback evidence. Avoid uncontrolled production experiments. Assign an expiry or event-driven recheck so the conclusion is not treated as permanent.\nOfficial references\n\nUse DNS Policy for Intelligent DNS Responses Based on the Time of Day — Microsoft",
                "datePublished": "2026-08-27T12:15:22+00:00",
                "dateModified": "2026-08-27T12:56:24+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/use-windows-time-of-day-dns-policies-only-with-deterministic-priority-and-fallback/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Use Windows time-of-day DNS policies only with deterministic priority and fallback"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 530,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use DNS Policy for Intelligent DNS Responses Based on the Time of Day",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/dns-tod-intelligent",
                    "datePublished": "2021-12-02"
                }
            }
        ]
    }
}