Raise Domain Functional Level Effects Of Changing
The domain functional level is programmatically raised to the second functional level by directly modifying the value of the msdsbehaviorversion attribute on the domaindns object.
Raise domain functional level effects of changing. When the domain functional level is raised it not possible to promote operating systems that are running earlier versions of the os. This password replication is a separate change within ad and occurs after the dfl has been raised. Therefore it is important that you decide which domain controllers exist on your network or may be added in the future prior to raising the level. After upgrading all dcs in the domain or forest the administrator is able to raise the functional level and this level acts as a flag informing the dcs and other components as well that certain features can now be enabled.
If older operating systems are used for domain controllers in the forest you will need to upgrade them before. As with domain functional levels raising the forest functional level is a one way change. Does this have any impact on sites hosted in iis using active directory domain services. Introduction this is a brief and high level blog on the windows domain functional level dfl.
After raising the level you cannot lower it. It is a good idea to know that during the process of raising the domain functional level dfl of your active directory structure from 2003 the krbtgt account password gets changed. Doesn t have a complete idea of all the sites whether they are using these active directory. Does raising domain functional level dfl have any impact on application using ad ds.
Having compromised a windows domain one of the things i like to do that i think adds real. Current dfl is windows 2003 and we are planning to raise it to windows 2008.