The following procedure requires access to Windows Server 2003 Support Tools. To install the Support Tools on a computer that is running Windows Server 2003, run the Setup.exe file from the \Support\Tools folder on the Windows Server 2003 CD.
Warning If you use the ADSI Edit snap-in, the LDP utility, or any other LDAP version 3 client, and you incorrectly modify the attributes of Active Directory objects, you can cause serious problems. These problems may require you to reinstall Microsoft Windows 2000 Server, Microsoft Windows Server 2003, Microsoft Exchange 2000 Server, Microsoft Exchange Server 2003, or both Windows and Exchange. Microsoft cannot guarantee that problems that occur if you incorrectly modify Active Directory object attributes can be solved. Modify these attributes at your own risk.
To resolve this issue, set permissions for the DnsAdmins group on the DomainDNSZones application partition and on the ForestDNSZones application partition. To do this, follow these steps:
- Log on to the Windows Server 2003-based DNS server as a user who has administrative rights.
- Set permissions for the DnsAdmins group on the DomainDNSZones application partition. To do this, follow these steps:
- Click Start, click Run, type Adsiedit.msc, and then click OK.
- In the task pane, right-click ADSI Edit, and then click Connect to.
- Under Connection Point, click Select or type a Distinguished Name or Naming Context, type the following, and then click OK:
CN=MicrosoftDNS,DC= DomainDNSZones,DC=Domain,DC=Domain_Extension
- In the task pane, locate and right-click CN=MicrosoftDNS,DC= DomainDNSZones,DC=Domain,DC=Domain_Extension, and then click Properties.
-
Click the Security tab, and then click Advanced.
The Advanced Security Settings for MicrosoftDNS dialog box appears.
- In the Permissions tab, click Add.
-
In the Enter the object name to select box, type DnsAdmins, and then click Check Names to verify the name.
- Click OK. The Permission Entry for Microsoft DNS dialog box appears.
- In the Apply onto drop-down list, click This object only.
- Click to select the Allow check box for the Full Control permission, and then click OK.
- In the Advanced Security Settings for MicrosoftDNS dialog box, click Apply, and then click OK.
- Click OK to close the properties dialog box for the DomainDNSZones application partition.
- Close the ADSI Edit window.
- Test whether you can create a new DNS zone now.
- Set permissions for the DnsAdmins group on the ForestDNSZones application partition. To do this, follow these steps:
- Click Start, click Run, type Adsiedit.msc, and then click OK.
- In the task pane, right-click ADSI Edit, and then click Connect to.
- Under Connection Point, click Select or type a Distinguished Name or Naming Context, type the following, and then click OK:
CN=MicrosoftDNS,DC= ForestDNSZones,DC=Domain,DC=Domain_Extension
- In the task pane, locate and right-click CN=MicrosoftDNS,DC= ForestDNSZones,DC=Domain,DC=Domain_Extension, and then click Properties.
-
Click the Security tab, and then click Advanced.
The Advanced Security Settings for MicrosoftDNS dialog box appears.
- In the Permissions tab, click Add.
-
In the Enter the object name to select box, type DnsAdmins, and then click Check Names to verify the name.
- Click OK. The Permission Entry for Microsoft DNS dialog box appears.
- In the Apply onto drop-down list, click This object only.
- Click to select the Allow check box for the Full Control permission, and then click OK.
- In the Advanced Security Settings for MicrosoftDNS dialog box, click Apply, and then click OK.
- Click OK to close the properties dialog box for the ForestDNSZones application partition.
- Close the ADSI Edit window.
- Test whether you can create a new DNS zone now.