Skip to main content
Version: 2.2.1-preview

AD-SCH-04 - Schema version details should be retrievable

Overviewโ€‹

Comprehensive schema information provides the foundation for understanding your Active Directory infrastructure. The schema defines:

  • Object classes: What types of objects can exist (users, computers, groups)
  • Attributes: What properties objects can have
  • Constraints: Rules for object creation and modification

Understanding schema details helps with:

  • Troubleshooting: Identifying schema-related issues
  • Planning: Preparing for application deployments
  • Documentation: Maintaining accurate AD documentation
  • Security: Detecting unauthorized schema modifications

Security Recommendationโ€‹

Protect your schema with these practices:

  • Schema Admins group: Keep membership minimal and monitored
  • Change control: Require approval for all schema modifications
  • Documentation: Maintain records of all schema extensions
  • Backup: Regularly backup the schema NC (naming context)
  • Monitoring: Alert on any schema modifications

How the Test Worksโ€‹

This test retrieves detailed information from the schema container including:

  • Schema version number
  • Corresponding Windows Server version
  • Schema creation and modification dates
  • Distribution of object classes
  • Total schema object count
  • Test-MtAdSchemaVersionEntryCount - Shows schema version number
  • Test-MtAdSchemaModificationYearCount - Shows modification timeline
  • Test-MtAdSchemaModificationYearDetails - Detailed modification breakdown

Test Metadataโ€‹

FieldValue
Test IDAD-SCH-04
SeverityInfo
SuiteActive Directory
CategoryAD.Schema
PowerShell testTest-MtAdSchemaVersionDetails
TagsAD, AD-SCH-04, AD.Schema

Sourceโ€‹

  • Pester test: tests/ad/schema/Test-MtAdSchemaVersionDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/schema/Test-MtAdSchemaVersionDetails.ps1