Your organization's risk policy requires separation of duties between AD schema modifications and day-to-day domain administration. Which built-in group assignment enforces this?
-
A
Assign day-to-day admins to the Schema Admins group with time-limited membership
-
B
Keep Schema Admins empty and add members only when schema changes are needed
-
C
Assign Schema Admins to a sub-OU with a restricted GPO
-
D
Use AGPM to require two approvals for schema modification requests