* Everything you wanted to know about schema extensions
endif; ?>Reaction continues to roll in regarding a recent newsletter that suggested network managers were still reluctant to extend the Active Directory schema. This is leading to a reluctance in installing services and applications that do an automatic extension as well as reluctance to use Windows servers to their full extent.
Concomitantly, of course, this reluctance gave rise to the need for Active Directory/Application Mode (ADAM) so that users could get the schema extensions they need without rustling the waters of the central IT masters.
A number of readers pointed me to what appears to be the source of people’s disquietude. Hidden within the Windows 2000 Server documentation (see link below), there is a passage that reads: “Extending the schema is a highly sensitive operation, with implications potentially throughout your network. Schema extension is best handled programmatically, and only when absolutely necessary. Improper schema modifications can impair or disable Windows 2000 Server and possibly your entire network.”
Well, that’s true, but the same could be said about modifying the registry, changing an INI file or many other modifications that managers and administrators are allowed to do. I was reminded that Novell, when it introduced directory service in NetWare 4, gave the same sort of warning to administrators who were also reluctant to change the schema. One difference, though, is that Novell recognized this problem and moved to let network managers know that, while a source of potential danger, schema extensions were a part of maintaining and improving the network and server and should be allowed whenever a need arose.
I should point out that the same Microsoft documentation also includes a “schema extension checklist” (link below), which implies to me, that extending the schema is an OK activity. Show this to the folks who are blocking your attempts to create an extension.
On the idea of Microsoft certifying extensions, a few of you pointed out that you can register an Object Identifier with Microsoft (link below) which, in effect, means that your OID won’t clash or conflict with another registered OID.
In reading about this topic at the Microsoft developer Web site, I also came across an article called “Extending the Schema” (link below), which is in the same document as the OID registration information. This could well have been subtitled: “Everything You Wanted to Know About Schema Extensions,” and should give you all the ammunition you need to proceed with a schema extension project.
I hope we can now lay the subject of whether or not to extend the schema to rest and get back to creating and maintaining a useful network and server. That’s my hope, but you know how these dead horses keep cropping up again and again.




