An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
If the DNS for the domain is hosted in Azure DNS, grant the IT company access by assigning them the DNS Zone Contributor role.
Two common options:
- Access to all DNS zones in a resource group
- In the Azure portal, open the resource group that contains the DNS zone.
- Select Access control (IAM).
- Select + Add.
- Choose the DNS Zone Contributor role.
- Select the user or group for the IT company.
- Access to only one DNS zone
- In the Azure portal, open the specific DNS zone for the domain.
- Select Access control (IAM).
- Select + Add.
- Choose the DNS Zone Contributor role.
- Select the user or group for the IT company.
This role lets them manage Azure DNS public DNS resources for the zone. It does not grant permissions to private DNS zones.
If only a specific record needs to be managed, Azure RBAC can also be applied at the record set level from the record set page by using the Users button.
For DMARC creation, the IT company typically needs permission to add or edit DNS records for the domain. If the domain is not hosted in Azure DNS, access must be granted at the domain registrar or current DNS hosting provider instead.