You must configure each subzones with the Update Policy deployment option.
For more information about the Update Policy DNS deployment option, refer to Configuring zones to accept GSS-TSIG updates.
To configure subzones:
-
Navigate to an AD subzone under default View> Top level zone (com)> Lower
level zone (example.com)> Subzones (_msdcs.example.com).
-
Click the Deployment Options tab.
-
Under Deployment Options, click
New and select DNS Option.
-
Under General, set the following options and click
Add.
- Option—Update Policy
- Privilege—grant
- Identity—select Name and type a client name in
the text field.
- Nametype—subdomain
- Name—enter the name of the current subzone (for
example, _msdcs.example.com)
- RR Types—ANY
-
Under Server, select the server to which the option will
apply.
-
Under Change
Control, add comments, if required.
-
Click Add.
-
Repeat this process for each of the AD subzones.
This completes all the necessary steps in Address Manager.
You need to deploy the configuration to a managed DNS Server. Perform a full
DNS deployment to the DNS Server.