Improve company productivity with a Business Account.Sign Up

x
?
Solved

Granting permissions to manage Windows DNS from different domain.

Posted on 2013-05-16
3
Medium Priority
?
440 Views
Last Modified: 2013-08-20
Hello,

I am trying to grant a user permissions to modify (add or delete) DNS entries in DomainA while they are logged into a server in DomainB.  There is a two way trust between the domains.

I have added them to the DNSAdmins group on DomainA.

We DO NOT want them to be Domain Admins on DomainA.

We cannot launch the dnsmgmt.mmc and connect to the DNS server. We can ping the server, but cannot connect.

We'd even be OK with using the dnscmd command line tool, but I got an access denied error when I tried that.

What other permissions do I need to set in order to get this work?
0
Comment
Question by:CanHasCheezburger
  • 2
3 Comments
 
LVL 22

Expert Comment

by:mcsween
ID: 39172503
How long did you wait after adding them to DNSAdmins?  You may have to wait for a directory sync to happen...

If you add them to the local administrators group on the DNS server can they do what they need?  (I know this isn't ideal; just for testing).
0
 
LVL 2

Author Comment

by:CanHasCheezburger
ID: 39172516
The DNS server is a Domain Controller. Don't want them to be domain admins.

I added them about 5 minutes before the test.
0
 
LVL 22

Accepted Solution

by:
mcsween earned 2000 total points
ID: 39172534
This describes a slightly different issue but sounds like it might be causing your issue too.  As these zones are probably created as domain or forest zones the DNSAdmins group doesn't have access to modify the zones or records within.

http://support.microsoft.com/kb/939090
0

Featured Post

Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This applies to Dell but may also apply to other manufacturers as well. We ran across a few machines that just dropped recently it trust relationship with the server. After doing the basic removing and joining the domain again, it changed to No logo…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question