Honestly, I’ve never thought about doing that. I’m pretty sure that Microsoft wants the secondary DNS servers to be AD type DNS servers if the zone was configured as an AD DNS domain. Now, you may find a complicated workaround, but you may want to create a subzone that is not an AD type to coordinate with your ZeroShell DNS.