Get the permissions of an Active Directory schema object

Viewed 361
  • PS Version: PowerShell 7+
  • OS Version: Windows Server 2016

Objective: I would like to use PowerShell to get the permissions of an AD schema object without the need of the Active Directory PsDrive / PsProvider.

The Active Directory PsProvider that comes with the AD Module does not work with PowerShell 7+ on Windows Server 2016 from my testing. This MS documentation also touches on that. Because that PsProvider is needed to create/use an Active Directory PsDrive, you can't access AD objects like this AD:\. Using this method is typically what I prefer. Below is an example of exactly what I need except I'm using Windows PowerShell and not PowerShell 7+.

This gets the configuration schema permissions:

(Get-Acl "AD:$((Get-ADRootDSE).schemaNamingContext)").Access

An example of the distinguished name for that object:

CN=Schema,CN=Configuration,DC=my,DC=domain,DC=com

With the limitations outlined, what other options within PowerShell 7+ can I use to access those permissions?

1 Answers

• According to the command that you have run on powershell in Windows Server 2016, it displays the active directory schema permissions of the concerned domain. But when running this command in my environment with Powershell 7.0+ installed as you can see in the image below, I got the same appropriate output as in normal powershell.

AD Schema permission

• Though you can change the permissions relating to schema objects by using the query as given below: -

Add ACL rule for the right "Read-write all properties/this object and all descendants" –

 $rootdse = Get-ADRootDSE
 $extendedrightsmap = @{}
 Get-ADObject -SearchBase ($rootdse.ConfigurationNamingContext) -LDAPFilter `
 "(&(objectclass=controlAccessRight)(rightsguid=*))" -Properties 
  displayName,rightsGuid | 
 % {$extendedrightsmap[$_.displayName]=[System.GUID]$_.rightsGuid}
 $extendedrightsmap

Please find the below link for more information: -

https://social.technet.microsoft.com/wiki/contents/articles/51121.active-directory-schema-update-and-custom-attribute.aspx

Related