The DNSAdmin group cannot use Powershell to obtain DNS information

fdsfsd zh 5 Reputation points

I try to execute the Powershell command to obtain DNS information through the pypsrp library of python. Executing Get-DnsServerResourceRecord through the Domain Admin group can return data, but the Dns Admin group does return empty

  1. I added user test1 to DnsAdmin
  2. Enable WMI related permissions
  3. Use the user to execute Get-AdUser to return data, and execute Get-DnsServerResourceRecord or Get-DnsServer to return empty

May I ask what is the problem? I also assigned the DNSAdmin group the Dns registry to no avail. Only the DomainAdmin group can, but I don’t want to set such a large authority to test1

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
4,871 questions
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
1,318 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. チャブーン 81 Reputation points MVP

    Hi, fdsfsd zh
    This is Chaboon.

    I tried executed Get-DnsServerResourceRecord on a Domain Controller, DNSAdmins Group is completed, but only Domain Users Group is not complated. Also , I tried executed Get-ADUser, DNSAdmins Group is completed, and Domain Users Group is complated. I do not configred WMI permissions.

    I seem ,you are not necessary to WMI permissions and must be setting "LocalAccountTokenFilterPolicy" registry.

    You can see below article :


    0 comments No comments

  2. fdsfsd zh 5 Reputation points
    0 comments No comments

  3. fdsfsd zh 5 Reputation points
    0 comments No comments