Configure a TSIG key on the nameserver and in Lattice. PowerDNS can use TSIG or its HTTP API. Embedded auth DNS is optional if you do not already run BIND.
Console

- DNS servers →
bind_tsig. Host, key name,secret_ref(env:orfile:). - Subnet: DDNS on, adapter
bind_tsig, zones e.g.office.example.com/20.20.10.in-addr.arpa.
Lab compose BIND profile: key name lattice. in deploy/compose/bind/named.conf. PowerDNS HTTP: PowerDNS.
Same rule as AD: the DHCP ack does not wait on the update.