Click here to get back home

Active Directory Schema Permissions

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Active Directory Schema Permissions Jonny613 10-17-2006
Posted by Jonny613 on October 17, 2006, 4:59 pm
Please log in for more thread options
I am unable to modify the Active Directory Schema.

The checkbox under Operations Master is greyed out. I am logged on under
the Administrator account and have verified that it is in the Schema Admins
group.

However, when I open the Active Directory Schema tool in mmc and check
permissions, it says that Administrators have no permissions. Authenticated
users have a read permission and Schema Admins do not have full control.

This is quite different from the settings in Active Directory Users and
Computers when I check the Schema Admins security options.

The Operations Master is set to my current machine.

Can someone tell me how to modify the security options for the Active
Directory Schema? Or if there is another location aside from Schema Admins

I have recently reinstalled Active Directory and Tools and am thinking that
something did not refresh properly that I am unaware of.



Posted by Jonny613 on October 18, 2006, 2:34 pm
Please log in for more thread options
I am still having this issue.

I was able to add the "Schema Update Allowed" registry key under HKEY LOCAL
MACHINE\System\CurrentControlSet\Services\NTDS\Parameters. This allowed me
to modify the schema with my ldifde but i still do not have the permissions
that I should (for example Administrators group is very limited, and when
logged in ad Administrator I can only View permissions).

"Jonny613" wrote:

> I am unable to modify the Active Directory Schema.
>
> The checkbox under Operations Master is greyed out. I am logged on under
> the Administrator account and have verified that it is in the Schema Admins
> group.
>
> However, when I open the Active Directory Schema tool in mmc and check
> permissions, it says that Administrators have no permissions. Authenticated
> users have a read permission and Schema Admins do not have full control.
>
> This is quite different from the settings in Active Directory Users and
> Computers when I check the Schema Admins security options.
>
> The Operations Master is set to my current machine.
>
> Can someone tell me how to modify the security options for the Active
> Directory Schema? Or if there is another location aside from Schema Admins
>
> I have recently reinstalled Active Directory and Tools and am thinking that
> something did not refresh properly that I am unaware of.
>
>

Posted by acchong on October 19, 2006, 4:21 pm
Please log in for more thread options
Select Advance from Permissions for Schema, go to owner tab, verify
that current owner is Schema Admins.
If not, select the option to change the owner to Schema Admins.

wrote:
> I am still having this issue.
>
> I was able to add the "Schema Update Allowed" registry key under HKEY LOCAL
> MACHINE\System\CurrentControlSet\Services\NTDS\Parameters. This allowed me
> to modify the schema with my ldifde but i still do not have the permissions
> that I should (for example Administrators group is very limited, and when
> logged in ad Administrator I can only View permissions).
>
>
>
> "Jonny613" wrote:
> > I am unable to modify the Active Directory Schema.
>
> > The checkbox under Operations Master is greyed out. I am logged on under
> > the Administrator account and have verified that it is in the Schema Admins
> > group.
>
> > However, when I open the Active Directory Schema tool in mmc and check
> > permissions, it says that Administrators have no permissions. Authenticated
> > users have a read permission and Schema Admins do not have full control.
>
> > This is quite different from the settings in Active Directory Users and
> > Computers when I check the Schema Admins security options.
>
> > The Operations Master is set to my current machine.
>
> > Can someone tell me how to modify the security options for the Active
> > Directory Schema? Or if there is another location aside from Schema Admins
>
> > I have recently reinstalled Active Directory and Tools and am thinking that
> > something did not refresh properly that I am unaware of.- Hide quoted text
-- Show quoted text -


Similar ThreadsPosted
auditing active directory not working properly directory serviceaccess October 21, 2005, 7:47 pm
Linking PKI directory accounts with Active Directory? February 11, 2007, 5:29 am
Active Directory December 28, 2005, 7:00 am
eap-tls without active directory November 23, 2006, 10:52 am
Active Directory May 1, 2008, 11:11 am
Active Directory Server August 12, 2005, 3:49 pm
Active Directory Questions. November 24, 2006, 12:09 am
Published Certificates in Active Directory February 9, 2006, 6:53 pm
Group Policy without Active Directory February 27, 2007, 3:31 pm
SAMR Interface Calls and Active Directory March 29, 2006, 8:16 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap