Skip to Content

Granting McNair Media DNS Access on Azure DNS

DNS Access Setup

Granting Us Access on Azure DNS

This page is for clients whose DNS lives in Microsoft Azure — a natural home if your business already runs on Microsoft 365. You'll assign McNair Media one built-in role, scoped to one DNS zone. It takes a few minutes in the Azure portal, touches none of your existing records, and is revocable by you at any time.

1 — Open Your DNS Zone

In the Azure portal, go to DNS zones and select your domain. Choose Access control (IAM) from the zone's menu — not from the subscription or resource group, so the grant stays scoped to this zone alone.

2 — Assign One Role

Click Add → Add role assignment, choose the built-in DNS Zone Contributor role, and assign it to the McNair Media application ID we supply. That role manages DNS records in this zone — it grants nothing anywhere else in your Azure estate.

3 — Tell Us It's Done

We confirm our access with a read-only check — we look at your website's current record and change nothing. From then on, automatic failover can act on your behalf the moment it's ever needed.

What This Does and Doesn't Allow

Narrow on Purpose

  • It allows: managing DNS records in this one zone — what automatic outage failover needs, and nothing more
  • It cannot: reach your subscriptions, resource groups, virtual machines, Microsoft 365 tenancy, or billing
  • Our written policy: we use this access for the records that route web traffic and for emergency failover. We do not modify mail records (MX, SPF, DKIM, DMARC) except on your written request — and every change we make appears in your Azure Activity Log as well as our own
  • To revoke: remove the role assignment on the zone's Access control (IAM) blade. Our access ends immediately