The Microsoft link at the bottom of an event log entry has gotten much better.

 

Mike Thommes

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DNA) [E]
Sent: Wednesday, May 24, 2006 10:21 AM
To: [email protected]
Subject: RE: [ActiveDir] view only rights on ADI DNS Zone

 

I was able to get a nice list of sources from EventcombMT.  So that will get me started, but if anyone has a good source with event ID’s that would be cool.

 

Todd

 


From: Al Mulnick [mailto:[EMAIL PROTECTED]
Sent: Wednesday, May 24, 2006 9:27 AM
To: [email protected]
Subject: Re: [ActiveDir] view only rights on ADI DNS Zone

 

You'll need a description of the rights needed to open the tool in this case, as everyone has read access by default. IIRC, the Windows 2000 DNS white paper describes how to delegate rights etc. using tools such as ADSIEDIT or DSACLS.  

 

Curious though: why bother? Read access to a DNS zone? Has the user ever used NSLOOKUP or DIG? You can read the zone records using these tools quite easily and it'll tell you just about everything you want to know about the RR.  Is there a different requirement in this?

 

Al

 

On 5/24/06, Kamlesh Parmar <[EMAIL PROTECTED]> wrote:

Is it possible to give normal domain account rights to view ADI DNS zone in console ?

 

I tried to give normal account a rights to READ thru ACL on zone, but it didn't help.

 

Only otherway, I know is to create a secondary for that zone, on that users machine. but thats overkilll :)

--

Kamlesh
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Be the change you want to see in the World"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Reply via email to