Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Granting permissions to manage Windows DNS from different domain.

Posted on 2013-05-16
3
Medium Priority
?
397 Views
Last Modified: 2013-08-20
Hello,

I am trying to grant a user permissions to modify (add or delete) DNS entries in DomainA while they are logged into a server in DomainB.  There is a two way trust between the domains.

I have added them to the DNSAdmins group on DomainA.

We DO NOT want them to be Domain Admins on DomainA.

We cannot launch the dnsmgmt.mmc and connect to the DNS server. We can ping the server, but cannot connect.

We'd even be OK with using the dnscmd command line tool, but I got an access denied error when I tried that.

What other permissions do I need to set in order to get this work?
0
Comment
Question by:CanHasCheezburger
  • 2
3 Comments
 
LVL 22

Expert Comment

by:mcsween
ID: 39172503
How long did you wait after adding them to DNSAdmins?  You may have to wait for a directory sync to happen...

If you add them to the local administrators group on the DNS server can they do what they need?  (I know this isn't ideal; just for testing).
0
 
LVL 2

Author Comment

by:CanHasCheezburger
ID: 39172516
The DNS server is a Domain Controller. Don't want them to be domain admins.

I added them about 5 minutes before the test.
0
 
LVL 22

Accepted Solution

by:
mcsween earned 2000 total points
ID: 39172534
This describes a slightly different issue but sounds like it might be causing your issue too.  As these zones are probably created as domain or forest zones the DNSAdmins group doesn't have access to modify the zones or records within.

http://support.microsoft.com/kb/939090
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

879 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question