Skip to main content

Cloud

DNS Permission Delegation

Sometimes in large organizations it is desirable to delegate the management of DNS to administrators other than full domain admins. Microsoft provides a group called DNSAdmins, however it does not have full control of all aspects of the DNS service. For instance, they can not create or delete AD integrated zones. You would think this is a right Microsoft would include with the default permissions, but it is not.

For customers that do need to delegate full control of even AD integrated DNS zones, there is a way to do it. It takes some editing with ADSI, but this is the PSS recommend method.

The two AD objects that need permissions changed are:

CN=MicrosoftDNS,DC=domaindnszones,dc=your,dc=domain

CN=MicrosoftDNS,DC=forestdnszones,dc=your,dc=domain

After this change, the DNSAdmins group will have virtually full control of all DNS zones and objects stored in AD. The permissions are:

Apply onto: dnsNode objects

Permissions: "Allow" for everything EXCEPT "Full Control" and "Modify Owner".

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Aaron Steele

More from this Author

Follow Us