The problem is that I see a lot of events 4662 in the AD Security log
(every few minutes), showing objects updating their entries in the
DomainDNSZone Partition. For me it seems like if the computers do not
have the right to update their own DNS entries
Concerning the Rights of the DNS-objects, "enterprise Domain
Controllers has full control" and System has Full control and
"Everyone" has Read-access.
Could there be something wrong in the DNS-server security
configuration or is there any modification to do if I want
workstations to update their own entries in DNS?
Here the detail about the event shown in the event log:
An operation was performed on an object.
Subject :
Security ID: DOMAIN\<PC NAME>$
Account Name: <PC NAME>$
Account Domain: Domain
Logon ID: 0x186984bd8
Object:
Object Server: DS
Object Type: dnsNode
Object Name: DC=<PC Name>,DC=Domain,CN=MicrosoftDNS,
DC=DomainDnsZones,....
Handle ID: 0x0
Operation:
Operation Type: Object Access
Accesses: Write Self
Access Mask: 0x8
Properties: ---
{771727b1-31b8-4cdf-ae62-4fe39fadf89e}
{e0fa1e69-9b45-11d0-afdd-00c04fd930c9}
{d5eb2eb7-be4e-463b-a214-634a44d7392e}
{e0fa1e8c-9b45-11d0-afdd-00c04fd930c9}