DNS issues

Author
Discussion

Regiment

Original Poster:

2,799 posts

159 months

Tuesday 31st March 2015
quotequote all
Bit techy but thought might help me with a broad range of people on the site.

Having an issue with DNS on our domain at work. It's only a minor issue but an issue none the less. If you log onto the dns server as the domain administrator account, you can't see the DNS entries at all, you can see the Forward Lookup Zones but they're pretty much empty, bar a few results. When I log in as my personal account, which is a domain admin, I see everything, all of the Forward Lookup Zones plus a full list of static and dynamic entries in the zones.

Security for the lookup zones give Domain Admins full access and confirmed that the administrator account and my account are in the domain admins group, anything obvious I might be missing? I'm not a member of a security group that the administrator isn't.

lestag

4,614 posts

276 months

Tuesday 31st March 2015
quotequote all
Regiment said:
Security for the lookup zones give Domain Admins full access and confirmed that the administrator account and my account are in the domain admins group, anything obvious I might be missing? I'm not a member of a security group that the administrator isn't.
log of the troublesome account and back in again? any security group changes will not happen until you have done that

theboss

6,913 posts

219 months

Tuesday 31st March 2015
quotequote all
Can you try running the DNS Management console in an elevated context? You probably have admin approval mode enabled for the local administrator account (rather than for all administrators) which, if you're running DNS on a DC, will mean the domain administrator account. This would explain the discrepancy between running DNS Management with administrator versus your own individual admin account.

Regiment

Original Poster:

2,799 posts

159 months

Tuesday 31st March 2015
quotequote all
Just tried running DNS console in an elevated mode unde the domain administrator account and get same thing, all other domain admins can see the entries without issue.

TonyRPH

12,971 posts

168 months

Wednesday 1st April 2015
quotequote all
Have you tried checking permissions in detail on individual zones?

Start by looking at top level permissions on the server itself, by viewing the security tab.

Than check the individual zones. By process of elimination you should be able to see which one has incorrect / missing permissions.



TurricanII

1,516 posts

198 months

Wednesday 1st April 2015
quotequote all
Can you see any Deny permissions for users or groups on the DNS zones when logged in as your working account?

I would run MMC, add the DNS server snap-in and connect to the DNS server again as a shot in the dark.