Windows Client 2.2.9 adds a fallback for undeclared private names
Earlier v2 releases refused private names such as .local, .corp, or
.internal with SERVFAIL when the name fell outside every Local
Forwarder rule. On a domain-joined device whose Active Directory domain
used one of those suffixes without a matching rule, domain controller
and other internal lookups under that domain failed.
Windows Client 2.2.9 adds a fallback. When no NRPT rule covers the name and the adapter Windows would use first has private resolvers, the client forwards the query to those resolvers and relays the answer. If none answer, the client returns SERVFAIL as before. Internal names only ever go to declared rules or to private resolvers on the network Windows would have used.
Declared Local Forwarder rules, public DNS policy, and DoH/DoT blocking are unchanged. Devices receive the fallback once they run 2.2.9, and no profile change is required. Declaring the domain as a Local Forwarder rule is still the recommended setup for AD-joined devices; see the Windows Client (v2) deployment guide.