This is from our network admin.
For the main domain's zone, on all DNS servers, and assuming that the Mac workstations are domain members, the following permissions apply:
Authenticated users get:
- Create All Child Objects (applies to This Object Only)
- Everything except Full Control...