Granting Us Access on Azure DNS
This page is for clients whose DNS lives in Microsoft Azure — a natural home if your business already runs on Microsoft 365. You'll assign McNair Media one built-in role, scoped to one DNS zone. It takes a few minutes in the Azure portal, touches none of your existing records, and is revocable by you at any time.
1 — Open Your DNS Zone
In the Azure portal, go to DNS zones and select your domain. Choose Access control (IAM) from the zone's menu — not from the subscription or resource group, so the grant stays scoped to this zone alone.
2 — Assign One Role
Click Add → Add role assignment, choose the built-in DNS Zone Contributor role, and assign it to the McNair Media application ID we supply. That role manages DNS records in this zone — it grants nothing anywhere else in your Azure estate.
3 — Tell Us It's Done
We confirm our access with a read-only check — we look at your website's current record and change nothing. From then on, automatic failover can act on your behalf the moment it's ever needed.
Narrow on Purpose
- It allows: managing DNS records in this one zone — what automatic outage failover needs, and nothing more
- It cannot: reach your subscriptions, resource groups, virtual machines, Microsoft 365 tenancy, or billing
- Our written policy: we use this access for the records that route web traffic and for emergency failover. We do not modify mail records (MX, SPF, DKIM, DMARC) except on your written request — and every change we make appears in your Azure Activity Log as well as our own
- To revoke: remove the role assignment on the zone's Access control (IAM) blade. Our access ends immediately