Our company is considering configuring workstations with static DNS servers that point to a cloud-based resolver where we can enforce security policies when the VPN is disconnected. If that configured resolver becomes unavailable, will Windows automatically switch to the DNS servers supplied by DHCP, or would name resolution stop working? We also need to account for office networks, Active Directory name resolution, hotel or home networks, and other adapters that users may connect through.
4 Answers
If you still choose static configuration, use multiple redundant resolvers rather than expecting DHCP to act as a fallback. Also remember that DNS settings are configured per network interface, so laptops may have separate settings for Wi-Fi, Ethernet, docks, and USB adapters. Managing those manually can become difficult, which is why a properly configured endpoint agent or always-on access solution is usually easier to maintain.
Be careful if the company uses Active Directory. Client DNS normally needs access to internal DNS servers that host the AD records; replacing those with an external cloud resolver can break authentication and service discovery. If the cloud resolver is managed by your organization and can resolve or forward the required internal records, it may work, but test domain logons, internal applications, and disconnected operation before deploying it broadly.
No. Once you configure DNS manually on a Windows network adapter, the DNS servers supplied by DHCP are ignored. If the static resolver is unavailable, Windows will not automatically revert to DHCP-provided DNS; lookups will fail unless another manually configured server is available. You can configure a second static resolver for redundancy, but make sure both are under your control and support the policies you need. Hardcoding public resolvers can also cause problems with internal Active Directory records, captive portals, and local network resolution.
For devices that move between office, home, and public networks, an always-on VPN or a SASE/ZTNA client is generally a better fit than changing adapter DNS settings. The client can apply filtering and security controls off-network while still allowing internal DNS and company resources to work correctly. Depending on the product, public traffic can either go directly to the internet or through the provider for filtering, inspection, and DLP.

That matches what our testing showed. We also tried a roaming DNS agent, but it has been inconsistent, so we are still evaluating alternatives.