I have multiple DNS servers and multiple domains running on Server 2008 R2.
I need to block a specific DC (dc1.sub1.domain.com) with DNS located at sub1.domain.com from adding a DNS server (DCa.domain.com) located at domain.com, to the DNS Management MMC.
The primary zone(AD-Integrated) is located on DCa.domain.com and is being replicated to all domains in the forest.
I found a work around.
Any DC can still add the server, but I restricted permissions on the DNS zones to read-only.
Microsoft is conducting an online survey to understand your opinion of the Technet Web site. If you choose to participate, the online survey will be presented to you when you leave the Technet Web site.
Would you like to participate?