AD-SCH-02 - Schema modification year details should be retrievable
Overviewβ
Detailed visibility into schema modifications by year provides a comprehensive timeline of your Active Directory's evolution. This information is valuable for:
- Capacity planning: Understanding growth patterns of the directory
- Change management: Tracking when major applications were deployed
- Security auditing: Identifying unauthorized or unexpected schema changes
- Compliance reporting: Documenting directory modifications for auditors
Unexpected spikes in schema modifications may indicate:
- Unauthorized application deployments
- Malicious schema extensions
- Improper testing procedures
- Lack of change control
Security Recommendationβ
Establish monitoring for schema changes:
- Alert on schema modifications: Configure alerts when schema changes occur
- Regular reviews: Periodically review schema modification history
- Access controls: Limit Schema Admins group membership
- Audit logging: Enable auditing for schema changes
How the Test Worksβ
This test analyzes schema objects and groups them by creation year, providing:
- Count of schema objects created per year
- Percentage distribution across years
- Timeline of directory evolution
Related Testsβ
Test-MtAdSchemaModificationYearCount- Shows count of years with modificationsTest-MtAdSchemaVersionEntryCount- Shows current schema versionTest-MtAdSchemaVersionDetails- Provides comprehensive schema details
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SCH-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Schema |
| PowerShell test | Test-MtAdSchemaModificationYearDetails |
| Tags | AD, AD-SCH-02, AD.Schema |
Sourceβ
- Pester test:
tests/ad/schema/Test-MtAdSchemaModificationYearDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/schema/Test-MtAdSchemaModificationYearDetails.ps1

