How to disable dynamic Kerberos SRV record or block dynamic updates

We have a Read Only Domain Controller in our domain used for LDAP integrations.  With the OS hardening that has been done, it does not support Kerberos authentications.  The primary Domain Controller auto updates the _kerberos SRV record hourly, so it is dynamically added back after we delete the record.  We have been unable to determine how to stop the auto updates from the DCs, so we are receiving a significant number of kerberos auth failures in our logs.


Is there a way to leave the SRV records in DNS, but set the record inactive or ignore/block the updates from the domain controller? 

