Highest Domain Functional Level
Domain functional level dfl determines the features of a domain controller dc based on the windows server operating system os it runs on.
Highest domain functional level. This way you can use as many ad ds features as possible. Having compromised a windows domain one of the things i like to do that i think adds real. If you are running exchange 2016 anywhere in your environment and if any of the domain controllers used by exchange are running windows server 2016 then the forest functional level must be raised to 2008r2 or later. Domain functional level and forest functional level can be seen in the general tab of properties.
Feature set of a particular dfl will be available for a dc if it runs on the operating system version that is compatible with the functional level. In our experience customers who keep their domain controllers deployed at the latest os revision level also employ the highest level of reliability security and. Open up powershell and run following cmdlets. Domain functional levels and forest functional levels.
Note that the os version constraint is only for the domain controller and not applicable for the member. Get adforest gets an active directory forest. From the administrative tools menu select active directory domains and trusts or active directory users and computers. Domain functional level settings the msds behavior version attribute is on the naming context nc head for the domain i e dc corp dc contoso dc com.
That is to provide support in a domain or forest for advanced active. Then get addomain format list domainmode get adforest format list forestmode. After all domain controllers are running an appropriate version of windows server the ad domain or ad forest must be configured to support the appropriate domain or forest functional level. When you change the functional level attributes manually the best practice is to make attribute changes on the flexible single master operations fsmo domain controller that is normally targeted by the microsoft administrative tools.
You can set the domain functional level to a value that is higher than the forest. Active directory functional level dependencies active directory domain and forest functionality has the following dependencies. When you deploy a new forest you are prompted to set the forest functional level and then set the domain functional level. Option 1 from admin tools.
There are some explanations with the functions up to windows server 2008 r2 and some on the differences between windows server 2008 r2 and windows server 2012. This is a brief and high level blog on the windows domain functional level dfl. Right click the root domain then select properties. Today i recognized that it is not easy to find a comprehensive summary table about active directory domain and forest functional levels operating mode on the internet.
The output would look like below. Under the general tab the domain functional level and forest functional level is displayed on the screen.