Jump to content

Recommended Posts

Posted

Good morning everyone!

 

I am currently in the process of creating dedicated accounts for a number of services that currently use domain admin credentials. One of these is DNS dynamic updates. The domain itself is 2003 functionality level, with 2003 DCs and DHCP and DNS on DCs.

 

Taking a look on the MS MVPs website (DHCP, Dynamic DNS Updates , Scavenging, static entries & time stamps, the DnsUpdateProxy Group, and DHCP Name Protection - AD and Exchange Quantum Singularity), I believe I need to do the following:

  1. Add DHCP DC to DnsUpdateProxy security group.
  2. Change DHCP to update all records.
  3. Secure update settings are already in place, so no need to change this.
  4. Create a standard domain user account and configure DNS dynamic updates to use this.
  5. Clear all current DNS entries.
  6. No 2008 R2 servers, so no securing DNS update proxy group or name protection.

Can anyone spot anything missing from this list? If not, that looks like quite a lot of change to enable a least privilege service account, and quite possibly a number of negative security changes. Would it be better to just create a service account with sufficient permissions to update DNS records, when required? If so, what permissions would such a service account require?

 

Thanks in advance for any help with this enquiry.

Posted

Do you have scavenging turned on for your DNS currently?

 

If So, I'd make the change but not carry out point 5, let the records scavenge out over time and anything new will be created by DHCP.

Unless of course you can be sure chaos won't ensue when mass deleting live DNS records all at once.

 

Other then that, you look spot on.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...