Skip to main content
Version: 2.2.1-preview

AD-SCH-03 - Schema version entry count should be retrievable

Overview​

The Active Directory schema version indicates the functional level and capabilities of your directory. Different schema versions correspond to different Windows Server releases:

Schema VersionWindows Server Version
13Windows 2000
30Windows Server 2003
44Windows Server 2008
47Windows Server 2008 R2
56Windows Server 2012
69Windows Server 2012 R2
87Windows Server 2016
88Windows Server 2019/2022

Knowing your schema version is important for:

  • Compatibility: Ensuring applications support your schema version
  • Feature availability: Understanding what AD features are available
  • Upgrade planning: Determining if schema updates are needed
  • Security: Newer schema versions support enhanced security features

Security Recommendation​

Keep your schema version current with your domain functional level:

  • Regular updates: Update schema when upgrading domain controllers
  • Feature enablement: Newer schemas enable security features like Authentication Policies
  • Application support: Modern applications may require newer schema versions

How the Test Works​

This test retrieves the objectVersion attribute from the schema container to determine the current schema version and maps it to the corresponding Windows Server version.

  • Test-MtAdSchemaVersionDetails - Provides comprehensive schema details
  • Test-MtAdSchemaModificationYearCount - Shows schema modification timeline
  • Test-MtAdDomainFunctionalLevel - Shows domain functional level

Test Metadata​

FieldValue
Test IDAD-SCH-03
SeverityInfo
SuiteActive Directory
CategoryAD.Schema
PowerShell testTest-MtAdSchemaVersionEntryCount
TagsAD, AD-SCH-03, AD.Schema

Source​

  • Pester test: tests/ad/schema/Test-MtAdSchemaVersionEntryCount.Tests.ps1
  • PowerShell source: powershell/public/ad/schema/Test-MtAdSchemaVersionEntryCount.ps1