Solved

DNS delegation option?? when promoting DC

Posted on 2015-01-28
3
151 Views
Last Modified: 2015-02-10
Hello,
Do we need to say Yes to "createDNSDelegation" option  when promoting 2012 DC? We want it to be DNS as well and we have DNS integrated zones. Do we need to say yes or no to CreateDNSDelegation?

THank you.

#
# Windows PowerShell script for AD DS Deployment
#

Import-Module ADDSDeployment
Install-ADDSDomainController `
-CreateDnsDelegation:$false `
0
Comment
Question by:creative555
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40576673
If there was a straight answer then it wouldn't be a choice. They include the option because you may or may not need it, depending on your unique environment. We can't answer that in a void.
0
 
LVL 6

Expert Comment

by:JeffG2583
ID: 40576677
Do you have a single domain under a single forest? How many DCs in the forest? You are fine answering No to creating a DNS delegation if you aren't interested in load balancing a lot of DNS requests. Here is a better description of it.

https://technet.microsoft.com/en-us/library/cc771640.aspx
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 500 total points
ID: 40576896
If you are promoting DC in root domain (single domain) \ Tree Root Domain then you would select No ($false) because domain.com is the authoritative zone for that DC for which delegation is not required

However if you are creating DC in child domain (child.domain.com), child domain by default is not authoritative for domain.com zone and hence delegation is required.
in that case you would select Yes ($true), in that case DNS delegation will be created on parent DNS server
If you have already logged on server with domain admins of parent domain the delegation will be automatically created OR you would be prompted for parent domain "domain admins" credentials so that delegation can be created in parent zone on parent dns server with the name of child domain (child)
This delegation contains NS record of child domain DNS server
The purpose of this delegation is to resolve queries related to child domain from parent domain
When you deploy 1st DC in child domain, delegation would be created in parent dns zone, when you add new DC in child domain, it will update that delegation by adding new NS record in existing delegation in parent zone
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question