Policy
Primary DNS suffix
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows2000, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2003, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista, WindowsXP
Specifies the primary DNS suffix used by the DNS client in DNS name registration and DNS name resolution. To use this policy setting, click Enabled and enter the entire primary DNS suffix you want to assign. For example: microsoft.com. Important: In order for changes to this policy setting to be applied on the DNS client, you must restart Windows. If you enable this policy setting, it supersedes the primary DNS suffix configured in the DNS Suffix and NetBIOS Computer Name dialog box using the System control panel. You can use this policy setting to prevent users, including local administrators, from changing the primary DNS suffix. If you disable this policy setting, or if you do not configure this policy setting, the DNS client uses the local primary DNS suffix, which is usually the DNS name of Active Directory domain to which it is joined.
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
Enter a primary DNS suffix: ID DNS_PrimaryDnsSuffixBox | text | HKLM\Software\Policies\Microsoft\System\DNSClient\NV PrimaryDnsSuffix Type REG_SZ | None |
Other policies in this category
Explore related policies at the same level.
- ComputerAllow DNS suffix appending to unqualified multi-label name queriesAt least Windows Vista
- ComputerAllow NetBT queries for fully qualified domain namesAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerConfigure Discovery of Designated Resolvers (DDR) protocolAt least Windows 11 Version 23H2
- ComputerConfigure encrypted name resolutionAt least Windows Server 20H2, Windows 10 Version 20H2
- ComputerConfigure multicast DNS (mDNS) protocolAt least Windows Server 2016, Windows 10 Version 1703
- ComputerConfigure NetBIOS settingsAt least Windows Vista
- ComputerConnection-specific DNS suffixWindows XP Professional only
- ComputerDNS serversWindows XP Professional only
- ComputerDNS suffix search listAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerDynamic updateAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerIDN mappingAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerPrefer link local responses over DNS when received over a network with higher precedenceAt least Windows Server 2012, Windows 8 or Windows RT