Solved

URGNET: Active Directory Schema Snap-in for MMC (basic question)

Posted on 2004-04-19
9
1,341 Views
Last Modified: 2010-04-13
When I click on Active Directory Schema, right click and select permissions, it will not let me change any of the permissions.

I am logged in as an Administrator, and I want to give the administrator group privelages to edit the schema
0
Comment
Question by:jjacksn
  • 3
  • 2
  • 2
  • +1
9 Comments
 
LVL 22

Accepted Solution

by:
Christopher McKay earned 200 total points
ID: 10866202
Hi jjacksn,
You may have to take ownership of it first.
(go into properties, then select Permissions, then select advanced, then take ownership)

Hope this helps!

:o)

Bartender_1
0
 
LVL 16

Expert Comment

by:JamesDS
ID: 10866206
jjacksn
Administrator does not have the rights by default. You need to add yourself to the Schema Admins groups

BE VERY CAREFUL schema changes are one way only on Windows 2000 and potential catastrophic.

Cheers

JamesDS
0
 
LVL 22

Expert Comment

by:Christopher McKay
ID: 10866222
jjacksn,
Sorry, that should be :
go into Properties, then select Security, then select advanced,the click on owner tab, then change the owner to you.

Hope this helps!

:o)

Bartender_1
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 
LVL 10

Expert Comment

by:anupnellip
ID: 10866378
default Administrator r by default in schema admin group . but other administrator whome you create later r not in this group . either add the user you wnat to admin schema to this group or log in as administrator .
0
 
LVL 16

Expert Comment

by:JamesDS
ID: 10866409
anupnellip

Sorry, you're right - to clarify

By default the domain administrator in the Forest root domain is a member of the schema admins group. Administrators created later and original administrators of the child domains are not member of the schema admins group

Cheers

James
0
 
LVL 5

Author Comment

by:jjacksn
ID: 10866459
I am the original Administrator account created when i installed the OS.  I am also the only computer in the Domain/Forrest.  Shouldn't I have rights by default according to what you are saying?
0
 
LVL 5

Author Comment

by:jjacksn
ID: 10866464
Also, when I select persmissions, It says that I can only view the other permissions, not chnage them.  Unfourtunately, I'm in the middle of updating it... so I will get back to you shortly when I can edit things.
0
 
LVL 5

Author Comment

by:jjacksn
ID: 10866583
"By default, all domain controllers permit Read access to the schema. A registry entry must be set on a domain controller to permit Write access to the schema on that domain controller. "
http://www.microsoft.com/windows2000/techinfo/planning/activedirectory/adschemasteps.asp

Do I need to change this?  If so, what is this registry key?
0
 
LVL 10

Assisted Solution

by:anupnellip
anupnellip earned 300 total points
ID: 10866636
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Remote desktop app for windows 2000 as a host - cheap and easy? 8 856
Domain dunctional level. 4 321
Windows 7 7 265
cant not receive emails, due to low disk space. 16 261
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question