What is best practice for this setting? It also goes by DNS Domain Name in DHCP scope settings.
The only documentation I can find about these suffixes and domain name settings specifies the the primary DNS name must match. (https://technet.microsoft.com/en-us/library/cc816716.aspx)
Lets say the AD domain is:
ad.example.com
DNS Zones include example.com. Some items, not all, that are joined to domain get aliases (either cname or a record) to domain joined machines. These are things link internal web servers and services that we don't want people to have to use service.ad.example.com.
Domain controllers are in several sites but FQDN of them would be something like loc-dc##.ad.example.com.
The issue isn't that I don't know what the setting does, but the above is our situation and we have some disputes about what this setting should be. I have my thoughts but I'd rather get some opinions or actual resources before I share them as to not bias any comments.