* A proposal for a "Schema Safe" certification for third-party schema extensions
I often hear about the reluctance people have to installing Active Directory or to extend it in any way. In particular, people seem to have a real reluctance to expand the Active Directory schema. When I wrote about this problem recently (see link below), Dee Dee LaBruyere, Protocom Development Systems’ perky marketing manager (Americas), dashed off a note that confirmed what others had been telling me, but which also offered a potential solution. What LaBruyere wrote was:
“I was at the Microsoft Worldwide Partner Conference in Toronto last week. One of my colleagues and I were chatting with a Microsoft Product Unit Manager for Unix solutions about bridging non-Microsoft platforms with Microsoft platforms. We agreed that we regularly encounter organizations who don’t want to extend the schema. (You may recall that Protocom SecureLogin Single Sign-On extends the Active Directory schema to manage and encrypt secure passwords and authentication credentials.) What occurred to me is that perhaps Microsoft would combat this problem if they implemented some sort of ‘Schema Safe’ certification for 3rd party schema extensions. In other words, if you’re an ISV whose technology/solution (whatever) requires a schema extension, one could submit that software to Microsoft certification processes to give end-user organizations peace of mind about safely extending their Active Directory schema.”
While at the Catalyst Conference last week, I asked a number of Microsoft partners three questions:
1) Does your product/application/service extend the schema?
2) Are users reluctant to do that?
3) Would Microsoft certified schema extensions make it easier?
Everyone who answered “yes” to the first question also answered “yes” to No. 2 and 3. It appears that all people want is an assurance that extending the schema won’t break anything nor will it interfere with upgrades or updates sometime down the road. The only organization that could give that assurance is Microsoft.
One longtime observer of Active Directory also pointed out that back at the time of Windows 2000’s release (with the first version of Active Directory), Microsoft spoke long and loud about the “dangers” of schema extension. Whether there were real dangers or not, or simply an attempt to forestall a tsunami of extensions, I’m not sure. What is certain is that schema extensions, when well thought out, present no problem. If it will take a statement and a certification from Microsoft to assure users of that, then I think Redmond should do that. Microsoft already does hardware and software certification, this is just a small extension (pun intended) of that service.




