Split-brain DNS configuration is important in certain situations in Office_365, such as when configuring single_sign-on with Active_Directory_Federation_Services (AD FS).
In this case, the address for connecting to AD_FS might be adfs.lucernepublishing.com. In addition, because the authentication process needs to be protected using Secure Sockets Layer (SSL) encryption, the common name (cn) or one of the subject alternate names (SANs) on the certificate must match the host name of the communication endpoint of the service.
The challenge here is that, in order to ensure a consistent experience for users, both internal and external clients will be connecting using the same host name.
In the case of AD_FS, there is an additional complication, in that internal clients connect directly to the AD_FS server farm, whereas external clients connect to the AD_FS_proxy_array. Hence, DNS needs to return a different IP address for internal and external clients