Archived from groups: microsoft.public.win2000.dns (More info?)
I need to be able to delegate the deletion of records to a group in
our organization that manages servers. These users are not domain
admins. I know that there is a DNS Administrators group, but that
grants WAY too much. I looked through all of the security priciples on
the objects for the zone, but could find nothing that made sense to
me. Nothing that I could attach to allowing only record deletion.
Is there any way to do this? if not, is there some combination of
limited rights that could come close?
I need to be able to delegate the deletion of records to a group in
our organization that manages servers. These users are not domain
admins. I know that there is a DNS Administrators group, but that
grants WAY too much. I looked through all of the security priciples on
the objects for the zone, but could find nothing that made sense to
me. Nothing that I could attach to allowing only record deletion.
Is there any way to do this? if not, is there some combination of
limited rights that could come close?