64
Distributed Link Tracking Server
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
TrkSvr Manual Disabled Disabled Disabled
The
Distributed Link Tracking Server
system service stores information so that files moved between
volumes can be tracked for each volume in the domain. When enabled, the
Distributed Link Tracking
Server
service runs on domain controllers. Therefore, this service is only set to
Automatic
in the
domain controller’s policy.
Distributed Transaction Coordinator
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
MSDTC Automatic Disabled Disabled Disabled
The
Distributed Transaction Coordinator
system service is responsible for coordinating transactions
that are distributed across multiple computer systems or resource managers, such as databases,
message queues, file systems, or other transaction-protected resource managers. This service is
configured to
Disabled
in the three environments defined in this guide.
DNS Client
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
Dnscache Automatic Automatic Automatic Automatic
The
DNS Client
system service resolves and caches DNS names for the computer. The DNS client
service must be running on every computer that performs DNS name resolution. Resolving DNS names
is essential for locating domain controllers in ActiveDirectory domains. Running the DNS client service
is also critical for locating devices identified using DNS name resolution. Therefore, this service setting
is configured to
Automatic
in the three environments defined in this guide.
DNS Server
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
DNS Not
installed Disabled Disabled Disabled
The
DNS Server
system service enables DNS name resolution by answering queries and update
requests for DNS names. The presence of a DNS server is crucial for locating devices identified using
DNS names and domain controllers in Active Directory. These functions are not needed on the
baseline server; they are only required on domain controllers. Therefore, this setting is disabled in the
baseline policy for the three environments defined in this guide. This value for this system service is set
to
Automatic
only on DNS servers in the three environments.