Unable to Modify the Active Directory Schema
Unable to modify the Schema
What to check for:
Event Type : Error
Event Source : NTDS General
Event Category: Internal Processing
Event ID : 1153
Date: MM/DD/YYYY
Time: HH:MM:SS AM|PM
User : Everyone Computer : <some DC>
Description: Class identifier 655562 (class name msWMI-MergeablePolicyTemplate) has an invalid superclass 655560. Inheritance ignored.
· This behavior occurs because the schema is imported in an order other than superclass inheritance. When a class is imported, superclass attributes point to other classes. Because these may not have been imported yet, you see these errors in the application event log.
- Is the user account being used to run Adprep a member of the necessary groups?
For a forest upgrade, the user must be a member of all 3: Enterprise Admins, Schema Admins, and Domain Admins (for the current domain).
For a domain upgrade, the user must be a member of at least Domain Admins for the targeted domain.
Error if the user is only a member of schema admins:
Adprep was unable to check the current user’s group membership.
[Status/Consequence]
Adprep has stopped without making changes.
[User Action]
Verify the current logged on user is a member of Domain Admins group, Enterprise Admins group and Schema Admins group if /forestprep is specified, or is a member of Domain Admins group if /domainprep is specified.
Adprep encountered a Win32 error.
Error code: 0×5 Error message: Access is denied..
[Status/Consequence]
Adprep has stopped without making changes.
[User Action]
Verify the current logged on user is a member of Enterprise Admins group, Schema Admins group and toll.com\Domain Admins group.
[Status/Consequence]
Adprep has stopped without making changes.
[User Action]
Verify the current logged on user is a member of Enterprise Admins group, Schema Admins group and toll.com\Domain Admins group.
Net User <username> /domain
User name Administrator
Full Name
Comment Built-in account for administering the computer/domain
User’s comment
Country code 000 (System Default)
Account active Yes
Account expires Never
Password expires Never
Password changeable
Password required Yes
User may change password Yes
Logon script
User profile
Home directory
Last logon
Global Group memberships *Schema Admins *
*Group Policy Creator *Domain Users
*Domain Admins
The command completed successfully.
· Related KBs:
http://support.microsoft.com/?id=293783
http://support.microsoft.com/?id=314649
Active Directory Active Directory Schema modify schemaActive Directory Active Directory Schema modify schema
Filed under: Active Directory


Leave a Reply