Re: 2003 Server DNS security



Thanks Todd, I have tried this, but it does not delegate permissions to
non-AD zones on a member server...

__
Matt


"Todd J Heron" <todd_heron_no_spam@xxxxxxxxxxx> wrote in message
news:O5kd4T4uFHA.3260@xxxxxxxxxxxxxxxxxxxxxxx
> Remove his local admin rights and instead make him a member of the "DNS
> Admins" group. That's what this group is for.
>
> --
> Todd J Heron, MCSE
> Windows Server 2003/2000/NT; CCA
> ----------------------------------------------------------------------------
> This posting is provided "as is" with no warranties and confers no rights
>
> "MattG" <email@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:%23Ux%23vT3uFHA.128@xxxxxxxxxxxxxxxxxxxxxxx
> I need to delegate permissions to enable a user to manage DNS on a member
> server hosting non-AD integrated DNS zones.
>
> Promoting the user to a local admin resolves the permission problem but
> also
> gives them access to things they shouldn't have access to, therefore this
> option is not viable.
>
> TIA...
>
>
>
> __
> Matt
>
>


.



Relevant Pages

  • Re: delegate admin rights to an user in an OU
    ... - install programs that need local admin rights ... administrators group on every client (with indirect I mean, ... admina member of an AD group and configure that AD group to be a member ...
    (microsoft.public.windows.server.active_directory)
  • Re: delegate admin rights to an OU
    ... - install programs that need local admin rights ... administrators group on every client (with indirect I mean, ... admina member of an AD group and configure that AD group to be a member ...
    (microsoft.public.windows.group_policy)
  • Re: 2003 Server DNS security
    ... Remove his local admin rights and instead make him a member of the "DNS ... I need to delegate permissions to enable a user to manage DNS on a member ... Promoting the user to a local admin resolves the permission problem but also ...
    (microsoft.public.windows.server.dns)
  • Re: Delegating Permissions
    ... You can not safely delegate permissions to modify a DC without giving enough rights for the delegate to escalate themselves to administrator, domain administrator, and eventually Enterprise Admin. ... Add/remove printers on DC ... We do not want local admin to have the right to backup up/restore files or manage or add printers on DC's outside of their division ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group member of another group
    ... Servers cannot support nested groups. ... I already have the local admin group added to ... group to the administrators group. ... You apparently have added a second domain group as a member of the local ...
    (microsoft.public.windows.server.active_directory)