Raise DFL and FFL level from 2008R2 to 2016

Garima Das 1,001 Reputation points
2024-04-25T09:15:31.5566667+00:00

Hello Everyone,

I have been working on an AD Modernization Project. Currently, in the environment, the Domain and Forest Functional levels are in 2008R2. I would like to raise the DFL and FFL level to Windows Server 2016. Since this is an irreversible process, I would like to understand the issues and risks involved with this process if I think to raise the DFL and FFL level from 2008R2 to directly 2016.

What would be the proper path to raise the DFL and FFL levels?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
{count} votes

Accepted answer
  1. Wesley Li 5,040 Reputation points
    2024-04-25T16:46:03.4433333+00:00

    Hello

    Raising the Domain Functional Level (DFL) and Forest Functional Level (FFL) from Windows Server 2008 R2 to Windows Server 2016 is a significant step in an Active Directory modernization project. Here are some key points to consider:

     

    Risks and Issues:

    Once the DFL and FFL have been upgraded, new Domain Controllers (DCs) running on downlevel versions of Windows Server cannot be added to the domain or forest.

    The problems that might arise when installing downlevel DCs become pronounced with new features that change the way objects are replicated (i.e., Linked Value Replication).

    The Windows Server 2008 R2 Domain or Forest Functional level can be lowered to Windows Server 2008, and no lower, if and only if none of the Active Directory features that require a Windows Server 2008 R2 Functional Level has been activated.

    Raising the DFL and FFL are one-way operations that cannot be reversed.

     

    Proper Path to Raise DFL and FFL Levels:

    Ensure all your domain controllers are running at least Windows Server 2008.

    Remove any domain controllers running on an unsupported version of Windows Server.

    If you created the domain at a lower functional level, you will need to migrate from using FRS to DFS replication for SYSVOL.

    Go to Active Directory Domains and Trusts. In the left pane, right-click on Active Directory Domains and Trusts and select Raise Forest Functional Level.

    Select the required functional level, in this case, select Windows Server 2016.

    Right-click on the domain name, and select Raise Domain Functional Level.

    In the window that opens, select the functional level Windows Server 2016, and click the Raise button.

     

    Functional levels do not affect which operating systems you can run on workstations and member servers that are joined to the domain or forest. So, your existing XP client and Windows 2003 member server will still be able to authenticate.

    0 comments No comments

0 additional answers

Sort by: Most helpful