Allow network Team (non domain Admins) to create AD integrated reverse lookup zones

Hi All

We wanted to enable our network guys to create DNS objects, so on the properties of our DNS servers (All AD running on 2008R2 DC's) we went into DNS on security tab and granted them read, write and create all child objects

The team are able to add A records and PTR records in existing zones but they need to be able to create AD integrated reverse lookup zones as they add new VLAN's

What's the best way to do this

Thanks
LVL 5
ncomperAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Will SzymkowskiSenior Solution ArchitectCommented:
You should just be able to add them to the Domain Local Group DnsAdmins in Active Directory. This will give them the option to create new reverse zones as necessary.


Thanks

Will.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
compdigit44Commented:
To add onto what Spec01 stated you may also want to enable DNS auditing so you can track who is creating / deleting objects in DNS as well.... ;-)


Just a suggestion..
0
ncomperAuthor Commented:
Thanks
0
ncomperAuthor Commented:
Hi

Just to update anyone who stumbles accross this thread in the future in order to create reverse lookup zones the DNSadmins group need some additonal permissions as detailed below in KB 939090 - it references 2003 but is valid for 2008  and R2 also.

Link to Microsoft KB article 939090
0
compdigit44Commented:
Thanks for the great tip!!!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.