I am migrating a Samba domain to AD on Windows 2k19. The domain successfully replicated, and I transferred 5 of the 7 Samba FSMOs (there are 2 additional FSMOs that Samba claimed that Active Directory documentation does not reference). The DNS zone was replicated successfully, and up until just recently I was able to add/edit records on the new server. However, I just started experiencing an issue where I can no longer add A records, or even create a new zone - every action I attempt results in "refused."
I am able to add/edit records on the old Samba server, which successfully replicate to the new server. I can also delete records on the new server, which successfully replicate to the Samba server.
Researching the issue, I found a suggestion to make a change to a group policy item, but that did not seem to help, and I haven't found any errors in the Event Log that would seem to point me to what the problem is.