Mandatory attributes that must be present on instances of the attribute's hosting class and that can be modified by the system only.
| Attribute property | Value | Description | 
|---|---|---|
| adminDisplayName | System-Must-Contain | Display name of this object for use in directory service administrative tools. | 
| adminDescription | System-Must-Contain | Description of this object for use in directory service administrative tools. | 
| cn | System-Must-Contain | Common name. | 
| lDAPDisplayName | systemMustContain | The name used by LDAP clients to refer to the object's class. | 
| attributeID | 1.2.840.113556.1.4.197 | A unique OID that identifies the attribute. | 
| objectClass | Attribute-Schema | The class of which this object is an instance. | 
| objectCategory | Attribute-Schema | Reference to an object class or one of its superclasses, which is used when searching for this object. | 
| schemaIDGUID | {BF967A45-0DE6-11D0-A285-00AA003049E2} | A GUID that uniquely identifies this object. You can use this string value in an ACE to control access to objects of this object. | 
| attributeSyntax | 2.5.5.2 | An OID of a syntax. The combination of the attributeSyntax and oMSyntax properties determines the syntax of an attribute. | 
| oMSyntax | 6 | Syntax of this attribute as defined by the XAPIA XOM (X/Open Object Model) specification. | 
| isSingleValued | FALSE | TRUE means that the attribute has a single value, FALSE means that the attribute can have multiple values. | 
| attributeSecurityGUID | -- not set -- | An optional GUID that identifies the attribute as a member of an attribute set(also known as a property set). | 
| showInAdvancedViewOnly | TRUE | TRUE means that the object will apear in the Advanced View of the Users and Computers snap-in only, but not in the Windows shell. FALSE means that the object will appear in Normal view of the Users and Computers snap-in and the Windows shell. | 
| systemFlags | 16 | An integer value that contains flags that define additional properties of this object. Category 1 classes or attributes have the 0x10 bit set by the system and cannot be set by users. They are shipped with Active Directory. For more information, see ADS_SYSETMFLAG_ENUM enumeration in ADSI Reference. | 
| systemOnly | TRUE | TRUE means that only Active Directory can modify the class of this object. FALSE means users can make the modification as well. | 
| Remarks | Same as Must-Contain but cannot be modified by the end-user. |