Raising DFL and FFL from 2012R2 to Highest Functional Level of 2016

Homer Sibayan 1 Reputation point
2021-04-07T07:35:29.73+00:00

Hi Experts!

Can someone give us the impact if we raise the Domain and Forest Functional Level of current DC 2016 which is currently 2012 R2 functional Level to the highest level of 2016? Currently we have a XP client and Windows Server 2003 member server running on the production.

I know that we can no longer be able to deploy domain controllers from older Version of Windows Server but what i am really worried is we have existing XP client and Windows 2003 member server.

In that case, if we raise it to 2016 Functional level are those XP and 2003 member server will still be able to authenticate ?

Thanks

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,389 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,534 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,932 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 18,721 Reputation points Microsoft Vendor
    2021-04-07T09:39:23.283+00:00

    Hello @Homer Sibayan ,

    Thank you for posting here.

    Generally raising function level will not impact member servers, because forest functional level and domain functional level are only for domain controller and not for member servers.

    Functional levels determine the available Active Directory Domain Services (AD DS) domain or forest capabilities. They also determine which Windows Server operating systems you can run on domain controllers in the domain or forest. However, functional levels do not affect which operating systems you can run on workstations and member servers that are joined to the domain or forest.

    We can see information below from the link below.

    There are two important restrictions of the Domain or Forest Functional Level to understand, and once they are, these restrictions are obvious. Once the Functional Level has been upgraded, new DCs on running on downlevel versions of Windows Server cannot be added to the domain or forest. The problems that might arise when installing downlevel DCs become pronounced with new features that change the way objects are replicated (i.e. Linked Value Replication). To prevent these issues from arising, a new DC must be at the same level, or greater, than the functional level of the domain or forest.

    The second restriction, for which there is a limited exception on Windows Server 2008 R2, is that once upgraded, the Domain or Forest Functional Level cannot later be downgraded. The only purpose that having such ability would serve would be so that downlevel DCs could be added to the domain. As has already been shown, this is generally a bad idea.

    85219-do1.png

    What is the Impact of Upgrading the Domain or Forest Functional Level?
    https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/what-is-the-impact-of-upgrading-the-domain-or-forest-functional/ba-p/399348

    And we can see Active Directory features related to Windows Server 2012 R2 domain functional level and forest functional level
    85281-do3.png

    Active Directory features related to Windows Server 2016 domain functional level and forest functional level
    85128-do2.png

    Forest and Domain Functional Levels
    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels

    Other references.

    Understanding Active Directory Domain Services (AD DS) Functional Levels
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc754918(v=ws.10)?redirectedfrom=MSDN

    Raise the Domain Functional Level
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753104(v=ws.11)

    Raise the Forest Functional Level
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc730985(v=ws.11)

    So if we raise it to 2016 Functional level, those XP and 2003 member server should be able to authenticate.

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments