DNS servers
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: Windows XP Professional only
Path in the GPO console
Computer Configuration\Administrative Templates\Network\DNS Client Description
Defines the DNS servers to which the DNS client sends queries when it attempts to resolve names. This policy setting supersedes the list of DNS servers configured locally and those configured using DHCP. To use this policy setting, click Enabled, and then enter a space-delimited list of IP addresses in the available field. To use this policy setting, you must enter at least one IP address. If you enable this policy setting, the list of DNS servers is applied to all network connections used by the DNS client. If you disable this policy setting, or if you do not configure this policy setting, the DNS client will use the local or DHCP supplied list of DNS servers, if configured.
Registry
Software\Policies\Microsoft\Windows NT\DNSClient MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_DnsClient/DNS_NameServer Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: DNS servers
; State: Enabled
; Supported on: Windows XP Professional only
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient]
"NameServer"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NameServer' -Value '' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_DnsClient/DNS_NameServer
Data type: String
Value:
<enabled/>
<data id="DNS_NameServerLabel" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient' -Name 'NameServer' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NameServer' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient' -Name 'NameServer' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: DNS servers
# State: Enabled
# Supported on: Windows XP Professional only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NameServer' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.