Every new version of Windows Server adds more features. Active Directory domain and forest functional levels determine the features that can be used within the system. You can check domain and forest functional levels using these steps. To find the Domain Functional Level, use this command: To find the Forest Functional Level, use this command: The domain functional level can be changed by right-clicking the domain and selecting Raise Domain Functional Level… Before doing this step, you must ensure that all domain controllers are running the version(s) of windows that allow for the change. For more information on raising domain and forest functional levels, visit the
Microsoft page – How to raise Active Directory domain and forest functional levels. The forest functional level can be changed by right-clicking Active Directory Domains and Trusts and selecting Raise Forest Functional Level… Before doing this
step, you must ensure that all domains in the forest are at the level required for the change. Reader InteractionsLike domain functional levels, the forest functional level determines which additional features in Active Directory will be available. In order to raise your forest functional level, all domains in the forest domain functional level must be at that corresponding forest functional level or higher. This video looks at the features that are available at each forest level and how to raise the forest level. Raise forest functional demo 17:45 When looking at an existing network with multiple domains, you need to consider the possibility that these domains were put in place originally due to limitations in Active Directory. Previously, Active Directory was not able to support more than one password policy per domain and even though the number was quite high, there were some limits on how many users could be put into certain groups. Because of these limits, more domains may have been created than would be required nowadays. When raising your domain and forest functional level, consider if any domains can be combined. Doing so will reduce the complexity of your network and make it easier to support. Forest Level Windows 2000 native Windows Server 2003 Rename Domains: This allows you to change a domain name. Link Value Replication: This means that only changes in group membership are replicated. Without link value replication, if a group is changed in two locations at once, the record with the newest time stamp is used replacing all the other records and thus all changes in those records are lost. Using link value replication also reduces the amount of data that is sent over the network during replication. Improved Knowledge Consistency Checker (KCC): The KCC is responsible for creating replication links between sites. With this forest functional level the KCC has been improved, particularly working with large deployments. Dynamic Auxiliary Class: Allows Active Directory objects to be created with an expiration time. Convert INetOrgPerson to user: Allows an INetOrgPerson object to be converted to a user object and vice versa. The INetOrgPerson object is used when importing or exporting users from Active Directory to a 3rd party directory system. Being able to convert a user object in Active Directory to an INetOrgPerson object makes the process of exporting and importing users with Active Directory a lot easier. Window Server 2008 RODC: This forest level is required if you want to start using Windows Server 2008 Read Only Domain Controllers in Active Directory. Deactivation of attributes: Once you make a change to the schema of Active Directory it can’t be deleted. Deactivation allows you to deactivate attributes in the Schema that are no longer required. Window Server 2008 Window Server 2008 R2 Raising the Forest Functional Level References Credits How do you raise the forest and domain functional level?From the Start menu, click on Administrative Tools. Select Active Directory Domains and Trusts. From the console, right click on Active Directory Domains and Trusts and select Raise Forest Functional Level. Choose the required value from Select an available forest functional level and click on Raise.
Is there a 2022 domain functional level?Just as there are no Windows Server 2019 Forest Functional Level (FFL) or Windows Server 2019 Domain Functional Level (DFL), there are no Windows Server 2022 FFL or DFL either in Microsoft Windows Server's Active Directory Domain Services (AD DS).
What tool is used to raise the forest functional levels?The most common method to enable the domain and forest functional levels is to use the graphical user interface (GUI) administration tools that are documented in the TechNet article about Windows Server 2003 Active Directory functional levels. This article discusses Windows Server 2003.
Which console can you use to raise the forest functional level in Active Directory?Increase the functional level of the forest
Open the Active Directory Domains and Trusts console, right-click Domains and Active Directory Approval 1 , and click Increase Functional Level of Forest 2 . Choose the forest target level 1 and click Increase 2 .
|