Raise Domain Functional Level Best Practices
Verify that active directory is replicating properly to all dcs.
Raise domain functional level best practices. The domain and forest functional levels are essentially just attributes in active directory. Select start administrative tools active directory domains and trusts. In the raise domain functional level select an available domain functional level from the drop down list. The functional level of the forest has been raised.
Upgrade them or remove them if needed. For example if you raise the domain functional level to windows server 2012 you will not be able to promote a server that is running windows server 2008 to domain controller. Right click the domain you want to raise the functional level of as in example below and then select raise domain functional level. The domain functional level for all domains must be properly replicated before you ll be able to raise the forest functional level.
You will notice that you don t need to do anything here as you. Identify and isolate dcs that run on earlier versions of windows server os. Raising the function level of the domain. The following are some of the best practices that can be adopted while raising the forest and or domain functional levels.
After the domain functional level is raised to a higher level it can only be changed back to an older level by. Navigate to start administrative tools active directory domains and trusts. If so that will block raising the domain functional level so you d better clean that up. Raising the functional level caution do not raise the functional level if the domain has or will have a domain controller that is of an earlier version than the version that is cited for that level.
For example a windows server 2008 functional level requires that all domain controllers have windows server 2008 or a later operating system installed in the domain or in the forest. If you re raising the functional level of a domain ensure that all the dcs in the domain is running os version that is compatible with the new functional level. Authentication errors may occur on a domain controller after the domain functional level is raised to windows server 2008 or higher if the domain controller has already replicated the dfl change but has not yet refreshed the krbtgt password. Verify the compatibility of enterprise applications and services with the target functional level.
Ensure that replication works properly. Open active directory domains and trusts. The functional level raise will be successful and the replication process will start between the domain controllers in the forest. Right click on the domain name in this example.