Solved

What is the purpose of Schema Admins?

Posted on 2008-10-07
4
1,009 Views
Last Modified: 2012-06-27
What is the purpose of Schema Admins in Active Directory Security Groups.
0
Comment
Question by:mlord_garan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 25 total points
ID: 22660132
At the risk of being obvious only users who are schema admins are allowed to make changes to the active directory schema - either via the ADSIEdit and and other tools or with ADprep etc.
0
 
LVL 26

Assisted Solution

by:MidnightOne
MidnightOne earned 25 total points
ID: 22660135
Schema Admins are the only users capable of modifying the schema in a Windows domain. Since schema additions cannot be removed once added, it's kind of important to limit even administrators from extending the schema without proper authority.
0
 
LVL 26

Expert Comment

by:Pber
ID: 22660165
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 22661137
Just to follow up on what Midnight said, Microsoft released a good white paper a few months ago on how they manage their Schema changes

http://technet.microsoft.com/en-us/library/bb687810.aspx
Structured Active Directory Schema Management at Microsoft

Good info in their, they certainly have very good processes.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question