Primary DNS Suffix change and Domain Trust issue


i have task change primary dns suffice from

eu.example.com uk.eu.example.com

if change manually in:

system propretis -> computer name -> change -> more -> primary dns suffix on computer.

it works fine , good.

however need on few machines, thought gpo it.

however gpo

computer configuration -> admin templates -> network -> dns client -> primary dns suffix

does diffrent, change nds suffix, change dont reflect in same gui manual change , can seen in ipconfig /all (but nevermind that),

the problem after reboot falls of domain giving:

the security database on server not have computer account workstation trust relationship

and way fix found go machine, login local admin, remove , readd machine domain.

is there way change primary dns suffix without machions losing domain trust ?

hi vladimir2989,

you can use policy setting prevent users, including local administrators, changing primary dns suffix.

by default, primary dns suffix portion of computer's fqdn same name of active directory domain computer joined. allow different primary dns suffixes, domain administrator can create restricted list of allowed suffixes modifying msds-alloweddnssuffixes attribute in domain object container. attribute managed domain administrator using active directory service interfaces (adsi) or lightweight directory access protocol (ldap).

if enable policy setting, supersedes primary dns suffix configured in dns suffix , netbios computer name dialog box using system control panel.

more detail steps please refer following kb:

configure primary dns suffix client computer

https://technet.microsoft.com/en-us/library/cc786695(v=ws.10).aspx

configure primary dns suffix client computer

https://technet.microsoft.com/en-us/library/cc794784(v=ws.10).aspx

understanding dns client settings

https://technet.microsoft.com/en-us/library/cc754152.aspx

configuring dns client settings

https://technet.microsoft.com/en-us/library/cc778792(v=ws.10).aspx

i’m glad of you!


please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group