Customers may be concerned that installing Safeguard Authentication Services (SAS) extends the Active Directory (AD) schema, and may want to know whether the schema can or should be restored to its default state after uninstalling the product.
This article clarifies whether SAS makes schema modifications and what actions, if any, are required during uninstallation.
Earlier versions of Windows Server (prior to Windows Server 2003 R2) did not include the UNIX user and group attributes required by Authentication Services. At that time, these attributes needed to be added to the AD schema.
Because of this historical behavior, some documentation, tooling, or user experience may still reference “schema changes,” which can lead to the assumption that modern versions of SAS actively extend the AD schema.
No schema restoration is required.
On supported and modern versions of Windows Server:
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center