Checklist: Deploying DNS for Active Directory

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2

Checklist: Deploying DNS for Active Directory

Step Reference

Review best practices for planning your deployment and use of Active Directory with Domain Name System (DNS).

DNS best practices; Active Directory Best practices

Understand how Active Directory integration works for DNS servers.

Active Directory integration

Consider additional advanced namespace design issues that can affect DNS namespace planning and use before finalizing your Active Directory namespace plans.

Obtain additional information resources on DNS namespace design available from either the Microsoft Web site or Microsoft Press books before for planning your network.

Namespace planning for DNS

Review all planning issues specific to deploying DNS servers on your network for supporting Active Directory.

Deploying DNS

Plan your namespace by specifying a domain name standard for your organization.

Namespace planning for DNS

If necessary, register your organization's domain name with the Internet domain name registrar. This name is then used to form the basis for DNS names your organization uses on the Internet and might also form the basis for names used internally on your intranet as well.

Internet DNS

Name: ____________________._____

Note

  • Registering a parent or second-level DNS domain name for your organization with an active Internet domain name registration authority is only required if you plan to use this name externally on the Internet.

Namespace planning for DNS; Namespace planning for DNS; Interoperability issues

Plan how to divide up your DNS domain name and network address space into forward and reverse lookup zones as needed.

Zone planning for DNS; Reverse lookup

Plan your DNS servers, such as determining how many servers you need to use and where to put them on your network.

For Active Directory, keep in mind that by default server computers promoted to be domain controllers also operate as DNS servers.

Server planning for DNS

(Optional) Test and evaluate server performance before finalizing your server plans. To perform DNS server evaluation, use related performance and event monitoring tools.

Monitoring and Optimizing Servers

Review additional migration and interoperability issues, if appropriate.

Migrating servers; Interoperability issues

If clients on your network need to be able to resolve external DNS names, consider whether you need to configure and use forwarders at DNS servers on your network.

Using forwarders; Configure a DNS server to use forwarders

Determine how to manage DNS client resolver configurations.

Managing Clients

If needed, add additional zones for any additional subdomains you need to add and use on your network.

Add a forward lookup zone; Add a reverse lookup zone

(Optional) Modify zone configurations to enable dynamic updates and change zone types to integrate storage of zones in Active Directory.

Allow dynamic updates; Change the zone type; Allow only secure dynamic updates

Install and configure domain controllers (or optionally, additional non-integrated DNS servers) and domains if they are to be used for hosting your zones.

Configure a DNS server for use with Active Directory; Install a DNS server; Configure a new DNS server

As needed, add delegations in parent zones for any subdomains added based on the previous step.

For example, if adding sub.example.microsoft.com as a new Active Directory domain, you would need to add to it a delegation at the example.microsoft.com zone.

Create a zone delegation; Delegating zones

(For standard primary zones only) Add new DNS servers you need to host your zones to the name server (NS) record at the primary zone/server to make them authoritative for the zone.

Specify other DNS servers as authoritative for a zone

Add DNS resource records--such as A, PTR, CNAME, and MX records--as needed to complete zone configurations.

Managing resource records; Add a resource record to a zone; Resource records reference

(Optional) Enable WINS lookup for selected zones.

Enable DNS to use WINS resolution

(Optional) Install and configure the DNS servers to act as secondary servers for your DNS deployment, if needed.

Install a DNS server; Add a secondary server for an existing zone; Using secondary servers

Use the monitoring features of the DNS console, such as simple or recursive query testing, to verify that DNS servers are operating correctly.

Monitor Servers

Troubleshoot DNS-related problems, if needed.

Troubleshooting DNS