Primary DNS Suffix change and Domain Trust issue
i have task change primary dns suffice from
eu.example.com uk.eu.example.com
if change manually in:
system propretis -> computer name -> change -> more -> primary dns suffix on computer.
it works fine , good.
however need on few machines, thought gpo it.
however gpo
computer configuration -> admin templates -> network -> dns client -> primary dns suffix
does diffrent, change nds suffix, change dont reflect in same gui manual change , can seen in ipconfig /all (but nevermind that),
the problem after reboot falls of domain giving:
the security database on server not have computer account workstation trust relationship
and way fix found go machine, login local admin, remove , readd machine domain.
is there way change primary dns suffix without machions losing domain trust ?
hi vladimir2989,
you can use policy setting prevent users, including local administrators, changing primary dns suffix.
by default, primary dns suffix portion of computer's fqdn same name of active directory domain computer joined. allow different primary dns suffixes, domain administrator can create restricted list of allowed suffixes modifying msds-alloweddnssuffixes attribute in domain object container. attribute managed domain administrator using active directory service interfaces (adsi) or lightweight directory access protocol (ldap).
if enable policy setting, supersedes primary dns suffix configured in dns suffix , netbios computer name dialog box using system control panel.
more detail steps please refer following kb:
configure primary dns suffix client computer
https://technet.microsoft.com/en-us/library/cc786695(v=ws.10).aspx
configure primary dns suffix client computer
https://technet.microsoft.com/en-us/library/cc794784(v=ws.10).aspx
understanding dns client settings
https://technet.microsoft.com/en-us/library/cc754152.aspx
configuring dns client settings
https://technet.microsoft.com/en-us/library/cc778792(v=ws.10).aspx
i’m glad of you!
please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com
Windows Server > Directory Services
Comments
Post a Comment