Implementing the Schema Administrators Role
Updated: December 5, 2005
Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2
The pre-defined Schema Admins security group (CN=Enterprise Admins, CN=Users, DC=<Forest-Root-Domain>) has all the permissions required to carry out all the responsibilities assigned to this role. Use this security group to represent this administrative role.
As a best-practice, keep the membership of this group empty and populate the membership of this group as and when a schema management administrative task needs to be performed.