# Check the DNS endpoint shape before putting a resolver balancer in front of NetApp Files

> Can a hostname-only DNS balancing service be entered in an Azure NetApp Files AD connection?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-211-check-the-dns-endpoint-shape-before-putting-a-resolver-balancer-in-front-of-netapp/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:25+00:00
- Modified: 2026-09-10T01:20:45+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Can a hostname-only DNS balancing service be entered in an Azure NetApp Files AD connection?

## Potentially affected

Review this constraint when proposing a resolver front end for an Azure NetApp Files AD connection. Identify the endpoint actually supplied by the chosen service rather than judging suitability from a product label.

## DSE recommendation

Require the network design to name the resolver endpoint address and the DNS servers behind it.

## Article

## Source facts

Azure NetApp Files accepts DNS server IP addresses in its Active Directory connection, not DNS server hostnames. A DNS load balancer is supported when it supplies an IP endpoint that can communicate over port 53 with the NetApp networks. DNS supports SMB access, NFSv4.1 Kerberos, LDAP, and Active Directory site discovery in this service. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/domain-name-system-concept).

## Applicability

Review this constraint when proposing a resolver front end for an Azure NetApp Files AD connection. Identify the endpoint actually supplied by the chosen service rather than judging suitability from a product label.

## DSE recommendation

Require the network design to name the resolver endpoint address and the DNS servers behind it. Have the directory owner confirm that the backend service can answer the required domain and service queries. Validate routing and firewall treatment from the delegated network, and document how a failed backend will be detected. Do not replace a server field with a friendly hostname and assume the platform will resolve it.

## Verification

Check the endpoint format against the connection’s accepted configuration before scheduling deployment. In a controlled test, verify relevant DNS answers through the proposed address and exercise representative directory-dependent volume access. Compare the answers and behavior with a known working resolver path. Keep endpoint reachability, correct DNS responses, and successful authenticated file access as separate evidence items.

## Official references

[Microsoft Learn: Understand Domain Name Systems in Azure NetApp Files](https://learn.microsoft.com/en-us/azure/azure-netapp-files/domain-name-system-concept).

## Primary reference

- Name: Understand Domain Name Systems in Azure NetApp Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-netapp-files/domain-name-system-concept
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the DNS endpoint shape before putting a resolver balancer in front of NetApp Files,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-211-check-the-dns-endpoint-shape-before-putting-a-resolver-balancer-in-front-of-netapp/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
