restrict DDNS to servers only


hello,

i'd restrict dynamic dns allow domain controllers , possibly member servers dynamically register.  appears done configuring dacl on ad integrated zones.  have specific information on how accomplish this?  documentation have been able find states adjust permissions not go detail far groups remove/add.

thanks,

dasani

using gpo, disable dns client service on machines other ones want register. registration service.

you can disable updates completely, , manually create required records. dcs, can use system32\config\netlogon.dns file created on each dc register zone srv records

if choose disable updates completely, make sure dcs register srv , other necessary records, can simply turn on updates short period while run ipconfig /all restart netlogon service on dcs, disabled updates. t

you can use acl, have extremely careful doing way. have link doc read? if so, please post it.

 


ace fekay
mvp, mct, mcitp ea, mcts windows 2008 & exchange 2007 & exchange 2010, exchange 2010 enterprise administrator, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php

this posting provided as-is no warranties or guarantees , confers no rights.

facebook twitter linkedin


Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS