When I joined my current company I was surprised to see that DNS was configured to allow non-secure dynamic updates to all of it's AD zones. I never didget a good answer for that design choice but it ...