PC Review


Reply
Thread Tools Rate Thread

Delegate Control to DNS Zone in Active Directory

 
 
MJC
Guest
Posts: n/a
 
      7th Sep 2007
How can I delegate control to a specific DNS zone to a non-domain admin
without adding that user to the "DNS Admins" group. Basically, I created a
zone on our DC for our Cisco devices. I want to grant our Network guys
administrative access to the zone without granting rights to all the zones
on the DC.

Thoughts?


 
Reply With Quote
 
 
 
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      8th Sep 2007
In news:%(E-Mail Removed),
MJC <(E-Mail Removed)> typed:
> How can I delegate control to a specific DNS zone to a non-domain
> admin without adding that user to the "DNS Admins" group. Basically,
> I created a zone on our DC for our Cisco devices. I want to grant our
> Network guys administrative access to the zone without granting
> rights to all the zones on the DC.
>
> Thoughts?


Keep in mind, DNS zone delegation is for delegating a child zone to a
different server(s). Therefore you can delegate this child zone (assuming
that is what you are talking about) to the DNS server that will be hosting
that zone and that they have control over. On that server, create the whole
child zone, such as childname.parentdomainname.com. THey will haev full
control over it and nothing else.

--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations

Having difficulty reading or finding responses to your post?
Try using Outlook Express or any other newsreader, configure a news
account, and point it to news.microsoft.com. Anonymous access. It's
easy and it's free:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

"Life isn't like a box of chocolates or a bowl of cherries or
peaches... Life is more like a jar of jalapenos. What you do today
may burn your butt tomorrow." - Garfield


 
Reply With Quote
 
MJC
Guest
Posts: n/a
 
      9th Sep 2007
I don't want to delgate a child zone to another DNS server, I want to
delegate control to a zone on my DNS server to a specific group of users.


"Ace Fekay [MVP]" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> In news:%(E-Mail Removed),
> MJC <(E-Mail Removed)> typed:
>> How can I delegate control to a specific DNS zone to a non-domain
>> admin without adding that user to the "DNS Admins" group. Basically,
>> I created a zone on our DC for our Cisco devices. I want to grant our
>> Network guys administrative access to the zone without granting
>> rights to all the zones on the DC.
>>
>> Thoughts?

>
> Keep in mind, DNS zone delegation is for delegating a child zone to a
> different server(s). Therefore you can delegate this child zone (assuming
> that is what you are talking about) to the DNS server that will be hosting
> that zone and that they have control over. On that server, create the
> whole child zone, such as childname.parentdomainname.com. THey will haev
> full control over it and nothing else.
>
> --
> Regards,
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
> MVP Microsoft MVP - Directory Services
> Microsoft Certified Trainer
>
> Infinite Diversities in Infinite Combinations
>
> Having difficulty reading or finding responses to your post?
> Try using Outlook Express or any other newsreader, configure a news
> account, and point it to news.microsoft.com. Anonymous access. It's
> easy and it's free:
>
> How to Configure OEx for Internet News
> http://support.microsoft.com/?id=171164
>
> "Life isn't like a box of chocolates or a bowl of cherries or
> peaches... Life is more like a jar of jalapenos. What you do today
> may burn your butt tomorrow." - Garfield
>



 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      11th Sep 2007
In news:(E-Mail Removed),
MJC <(E-Mail Removed)> typed:
> I don't want to delgate a child zone to another DNS server, I want to
> delegate control to a zone on my DNS server to a specific group of
> users.


I know some folks that have had trouble finiting the permissions to make
this work. Have you tried using the DnsAdmin Group? I believe, IIRC, the
user also needs local machine admin rights, but you will need to test that.
with a test account.

Ace


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Active Directory-integrated Zone =?Utf-8?B?TGlzYQ==?= Microsoft Windows 2000 Networking 3 2nd Sep 2005 07:21 PM
Active Directory Integrated Zone Jonas, Sylvan R. Microsoft Windows 2000 Active Directory 6 2nd Mar 2005 07:14 PM
Delegate Control of Active Directory =?Utf-8?B?YmFubnk=?= Microsoft Windows 2000 Active Directory 4 12th Aug 2004 02:06 PM
Active directory zone problem Lex Microsoft Windows 2000 DNS 2 21st Feb 2004 03:46 AM
Delegate Control of an object in Active Directory Programmatically =?Utf-8?B?RnJhbmtsaW4gWmFiYWxh?= Microsoft C# .NET 0 19th Feb 2004 09:01 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:05 AM.