You need to ensure that only authenticated users are allowed to update host (A) records in the DNS zone
You need to grant members of the Account Operators group the ability to only manage Basic EFS certificates