R
Randy Barger \(ConsultIT\)
I have a client who wants to separate the DNS Admin role from the Active
Directory admins. Essentially, only members of the DnsAdmins group should
have rights to administer DNS. Administrators should still be able to view
the zone, just not change records and settings. I want to use the Security
tabs to lock this down. Yes, I'm aware that Administrators would still have
the ability to "reset" the Security tab and get in, but we can audit that,
so that's ok.
What I'm looking for is a document or set of recommendations on specifically
what rights I should remove, and whether I should do this on the server
properties or the zone properties.
Thanks!
Randy Barger
MCT, MCSE, MCSA, CCNA, CCA, CNA
__________________________________________________
ConsultIT - http://ConsultIT.bizhosting.com/
Improving business through technology.
Directory admins. Essentially, only members of the DnsAdmins group should
have rights to administer DNS. Administrators should still be able to view
the zone, just not change records and settings. I want to use the Security
tabs to lock this down. Yes, I'm aware that Administrators would still have
the ability to "reset" the Security tab and get in, but we can audit that,
so that's ok.
What I'm looking for is a document or set of recommendations on specifically
what rights I should remove, and whether I should do this on the server
properties or the zone properties.
Thanks!
Randy Barger
MCT, MCSE, MCSA, CCNA, CCA, CNA
__________________________________________________
ConsultIT - http://ConsultIT.bizhosting.com/
Improving business through technology.