howartp Posted April 23, 2021 Posted April 23, 2021 Good morning We discovered the Add-DnsServerQueryResolutionPolicy cmdlet and its associated friends for ZoneScopes and ClientSubnets yesterday. We have split DNS (.school.internal and .myschool.com) served by our DC DNS servers. Both LAN PCs and iPads use the internal DNS. We have two ADFS servers - one internal (using integrated windows auth) and one proxy (using forms-based auth). The problem we're trying to solve, through which we discovered the above policies, is that iPads are hitting the internal ADFS and trying to use integrated auth. I tested the policies on a nonexistent domain yesterday which worked great, for the one URL I was testing. When I implemented live, I discovered that only entering the one URL works great for that URL, but all other *.myschool.com URLS return no result unless I re-add them to all the ZoneScopes. Does anyone know if it's possible to "fall through" so if a ZoneScope doesn't contain an entry it falls back to the parent scope that shows in DNS Management? I really don't want to add and maintain separate DNS records for four scopes just for the sake of one server. Peter
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now