---
title: "Microsoft DNS - Service Locations"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1710195899/Microsoft%20DNS%20-%20Service%20Locations"
format: markdown
---
- In the **Service Location** step of the **Configure Discovery** wizard, configure the following:
  - Click **Add** and configure the following:
    - **Universal Agent**: Choose the Universal Agent from the drop-down.
    - The DNS Server field is used to define the IP address of the DNS server you want to connect to, while Resolved IP refers to the final resolved address of that DNS server once DNS lookup is performed. Although the fields allow direct IP input, it is strongly recommended to specify the FQDN (Fully Qualified Domain Name) of the DNS server instead of using a raw IP address. Using the FQDN enables proper domain-based authentication and service resolution, which in turn allows the system to use Kerberos authentication rather than falling back to NTLM. Kerberos is more secure, supports mutual authentication, and is the preferred method in Active Directory environments, whereas NTLM is older, less secure, and often used only when the system cannot identify the target through domain-based name resolution. Click **Add** and configure the following:
      - **DNS Server**: Specify the IP address of FQDN of the DNS server. It is recommended to specify the FQDN for this field. You can add multiple DNS servers.
      - **Resolved IP**: Specify the resolved IP of the DNS server you want to manage.
    - **Credentials**: Choose the credentials from the drop-down. For more information on creating new credentials, see *[Creating Active Directory Credentials](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1693876284)**.*
  - Click **Save**.
- Click **Next**.