At Tue, 30 Dec 2008 16:05:10 +0100, Nico De Ranter wrote: > > update-policy { > grant TEST.NET krb5-subdomain * A; > }; Microsoft invented their own naming scheme for host principals ("machine$@realm" instead of "host/machine at realm"). Try "ms-subdomain" instead of "krb5-subdomain".