Because security is often a main concern in some environments, could there be a feature that disables DNS Zone Transfers when configuring DNS monitoring and possibly a separate sevice account or role based account that could be enabled for such configuration without having all of the admin or domain admin rights? Thanks for the opportunity to submit input.