Home › Active Directory basics: how AD DS is built › Step 2

The AD DS schema: classes, attributes and the schema master

Step 2 of 6 in Active Directory basics: how AD DS is built · video 3:31

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The schema is the rulebook of Active Directory: it defines every object class and attribute that AD DS can store, and the syntax of each value. This lesson explains that there is one schema per forest, copied to every domain controller, and that changes flow out from the domain controller holding the schema master operations role, usually the first DC in the forest. It shows how classes group attributes into mandatory and optional sets, using the user class and its hundreds of possible attributes as the example. It then sets out the rules for changing the schema: only Schema Admins may do it, nothing can be deleted, only extended, and extensions such as those applied before installing Exchange Server touch the whole forest. Because every change is forest-wide and permanent, the lesson stresses reviewing and testing first, then making the change with the Active Directory Schema snap-in pointed at the schema master.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which group's members are allowed to modify the AD DS schema?

Only members of Schema Admins. Access is kept that narrow because any schema change affects every domain controller in the forest.

2. Can the directory create an object whose type the schema does not define?

No. Whenever the directory stores data it looks up the matching object definition in the schema and builds the object from it, so only schema-defined classes can exist. This fixed format is what lets AD DS validate data whichever application supplies it.

3. What happens if an administrator adds an unwanted attribute to the schema and later wants to delete it?

It cannot be deleted: the schema can only be extended or have existing definitions modified. That is why the lesson insists on reviewing and testing schema changes before applying them.

4. Your team is about to install Exchange Server in the forest; what schema step comes first, and where must the change be made?

The Exchange schema extensions must be applied first, adding or changing hundreds of classes and attributes. The change is made against the domain controller holding the schema master role, which then replicates it to every DC in the forest.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Introduction and Administration Tools

4.4★ · 10,857 students on Udemy

See the course on Udemy
← AD DS components: logical and physical building blocksNext: The AD DS forest: root domain, security and replication boundary →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.