all authenticated users can create RRs in DNS zones.
so if you configure your DHCP with a SIMPLE user account (not special) only
that account will be able to update the RRs (and all other security
principals in the ACL, which are admins and the DCs)
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)-->
http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)-->
http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> Roger,
>
> I agree with you that theoretically I can preserve integrity of
> important DNS records by preventing DHCP from rewriting them. But in
> practice, what can I do?
>
> Microsoft recommends to run DHCP under a low privilege account.
> I am wondering why Microsoft omits in their docs any recommendations on
> ACL that this account must have on DNS zones.
>
> Suppose, I have one zone with 4000 workstations and 300 servers. The
> DHCP server acts under a specific AD account. I do not want to tweak
> ACLs on every single record in my DNS zone.
>
> What permissions should I give to the DHCP account on my DNS zone?
>
> May be something like this?
>
> Domain Computers = Create child objects
> CREATOR/OWNER = Full Control
>