The Access Template
DNS Admins - Microsoft DNS Management must be applied in one of the following or both based on the Active Directory infrastructure:
<Forest-Root-Domain>/ForestDnsZones/MicrosoftDNS
<Domain>/System/MicrosoftDNS
<Domain>/DomainDnsZones/MicrosoftDNS
1) Open Active Roles MMC;
2) Expand Active Directory | domain.local | System | MicrosoftDNS;
3) Right-click under the MicrosoftDNS and click Delegate Control...;
4) On the Active Roles Secitury window click on Add... button;
5) On the Delegation Control Wizard click Next;
6) Add the user or group to grant permission and then click Next;
7) On the Access Template window expand Active Directory | Best Practices for Delegation Active Directory Administration | DNS Admin Role and check off the "DNS Admin - Microsoft DNS Management" AT;
8) On the Inheritance Option click Next:
9) On Permissions Propagation window check off the box to Propagate permission to Active Directory and click Next;
10) Click Finish to complete;
Once the permission has been granted and replicated across the forest/domain, the user can connect to the DNS using the DNS Management console.