Bryan O'Connor | 16 April 2013
In traditional DNS, the DNS records are stored inside files, this works. With Windows 2012 we have the ability to store the DNS records in Active Directory, this in turn leads to secure storage, more efficient replication and a multi master DNS model.
One of the courses I teach is the
Microsoft Windows 2012 Installing and Configuring course, the
Microsoft designation is the 20410B
In the presentation, we look at creating an Active Directory Integrated DNS zone in Microsoft Windows Server 2012.
A DNS server can store zone data in the AD DS database provided that the DNS server is an AD DS domain controller. When the DNS server stores zone data in this way, this creates an Active Directory Integrated zone.
The benefits of an Active Directory-integrated zone are significant:
Multi master updates. Unlike standard primary zones which can only be modified by a single primary serve Active Directory Integrated zones can be written to by any writable domain controller to which the zone is replicated. This builds redundancy into the DNS infrastructure. In addition, Multi master updates are particularly important in geographically distributed organizations that use dynamic update zones, because clients can update their DNS records without having to connect to a potentially geographically distant primary server.
Replication of DNS zone data by using AD DS replication. One of the characteristics of Active Directory replication is attribute level replication in which only changed attributes are replicated. An Active Directory Integrated zone can leverage these benefits of Active Directory replication, rather than replicating the entire zone file as in traditional DNS zone transfer models.
Secure dynamic updates. An Active Directory-integrated zone can enforce secure dynamic updates.
Granular security. As with other Active Directory objects, an Active Directory-integrated zone allows you to delegate administration of zones, domains, and resource records by modifying the access control list (ACL) on the zone.
The demonstration is available at the BryanQA Youtube site