Solved

Granting permissions to manage Windows DNS from different domain.

Posted on 2013-05-16
3
319 Views
Last Modified: 2013-08-20
Hello,

I am trying to grant a user permissions to modify (add or delete) DNS entries in DomainA while they are logged into a server in DomainB.  There is a two way trust between the domains.

I have added them to the DNSAdmins group on DomainA.

We DO NOT want them to be Domain Admins on DomainA.

We cannot launch the dnsmgmt.mmc and connect to the DNS server. We can ping the server, but cannot connect.

We'd even be OK with using the dnscmd command line tool, but I got an access denied error when I tried that.

What other permissions do I need to set in order to get this work?
0
Comment
Question by:CanHasCheezburger
  • 2
3 Comments
 
LVL 22

Expert Comment

by:mcsween
ID: 39172503
How long did you wait after adding them to DNSAdmins?  You may have to wait for a directory sync to happen...

If you add them to the local administrators group on the DNS server can they do what they need?  (I know this isn't ideal; just for testing).
0
 
LVL 2

Author Comment

by:CanHasCheezburger
ID: 39172516
The DNS server is a Domain Controller. Don't want them to be domain admins.

I added them about 5 minutes before the test.
0
 
LVL 22

Accepted Solution

by:
mcsween earned 500 total points
ID: 39172534
This describes a slightly different issue but sounds like it might be causing your issue too.  As these zones are probably created as domain or forest zones the DNSAdmins group doesn't have access to modify the zones or records within.

http://support.microsoft.com/kb/939090
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question