AD Schema Security

From: SKM (anonymous_at_discussions.microsoft.com)
Date: 02/18/04


Date: Wed, 18 Feb 2004 03:41:07 -0800

Hi all

Is there a "backdoor" or way for an application installation to
programmatically, get elevated privileges to update the AD schema?

Eg. the Schema Admins group is empty and the Schema partition is not set to
be writable, however an end-user attempts to install an application on their
workstation which tries to update the schema as part of the install. To be
able to isntall the app the application is already in an elevated privilege
state. Is there a way to ensure that there is no chance a rogue app
installed by an end-user can update the schema?
I would like to ensure that in this situation, the schema update by the
users application install should FAIL

Thanks

 
  
  
 



Relevant Pages

  • Re: 2008 or 2003
    ... To install a 2008 DC in a 2003 domain the schema has to be upgraded to version 44. ... The schema is the same in your complete domain, the schema upgrade will add additional AD objects which are needed for 2008. ... 2008 ad schema instead of setting it up as a 2003 AD server I need all ...
    (microsoft.public.windows.server.setup)
  • Re: Uupgrade to Server 2003 R2 AD
    ... You run adprep on the schema master then you can install the R2 ... the updated features on. ... on the schema master for your domain from the *first* disk of the R2 set. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DFS Replication setup in Server2k3 R2
    ... I imagine the first fact is I never extended the schema. ... default when you put cd2 in during the install? ... The DFS Replication service successfully configured the debug log files. ... installed Server 2003 R2 on three servers and setup users, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Fouled up Exchange 2003 installation
    ... you need to verify the condition of your schema at this point. ... Typically you install schema extensions directly on a root domain DC. ... Not realizing that Exchange would not run on x64 platform, ...
    (microsoft.public.exchange.setup)
  • Re: New 2003 DC
    ... one server running Exchange 2000. ... I plan to install a new server, which needs to be a domain controller, ... There is a schema conflict with Exchange 2000. ...
    (microsoft.public.win2000.active_directory)