Domain Functional Level 2012 Vs 2012 R2
During adds deployment if you have set forest functional level to windows server 2012 r2 you cannot set the domain functional level lower than windows server 2012 r2 like windows server 2008 or 2003.
Domain functional level 2012 vs 2012 r2. Protected users authenticating to a windows server 2012 r2 domain can no longer. If you have to revert to a lower functional level with a version of windows server that is earlier than windows server 2008 r2 you must rebuild the domain or forest or restore it from a backup copy. All default active directory features all features from the windows server 2012 domain functional level plus the following features. Authenticate with ntlm authentication.
As you can see the domain with a dfl of windows server 2012 r2 on the left has the additional redtrictedadmin option with mstsc exe while the domain with a dfl of windows 2008 does not. What is meant by forest and domain functional levels. There are some explanations with the functions up to windows server 2008 r2 and some on the differences between windows server 2008 r2 and windows server 2012. For example to set the domain functional level to 2008 r2.
Ich musste heute leider feststellen dass es nicht so einfach ist im internet eine umfassende übersichtstabelle über active directory domain und forest functional levels betriebmodus zu finden. Es sind im windows server 2008 modus ausgeführte domänenbasierte dfs namespaces einschließlich der unterstützung für die zugriffsbasierte aufzählung und bessere skalierbarkeit verfügbar. Suppose when you have set forest and domain functional level to windows server 2016 you cannot add dc s running windows server 2012 or 2008. Today i recognized that it is not easy to find a comprehensive summary table about active directory domain and forest functional levels operating mode on the internet.
Viele beschäftigen sich nur mit den funktionen bis zur windows server 2008r2 andere betrachten nur den unterschied zwischen windows server2008r2 und windows server 2012. A new domain that is created on a domain controller that runs at least windows server 2012 r2 must be set to the windows server 2008 domain functional level or higher. Kerberos improvements from windows server 2012 and 2012 r2 are not implemented in samba. With windows server 2012 and r2 it is possible to roll back forest and domain functional level with limitation as defined in table in the link.
To raise the domain functional level on a samba active directory ad domain controller dc use samba tool.