Domain Functional Level 2012 R2
Today i recognized that it is not easy to find a comprehensive summary table about active directory domain and forest functional levels operating mode on the internet.
Domain functional level 2012 r2. Windows server 2012 r2 functional level. I don t know why it s this way as i just found this out today. The advice is to downgrade the forest and domain functional level on the windows dc to 2008 r2 and turn off all the associated features in 2012 before joining samba.
Adding 2012 r2 domain controller to 2016 functional level domain. A new domain that is created on a domain controller that runs at least windows server 2012 r2 must be set to the windows server 2008 domain functional level or higher. To downgrade the domain forest functional level there are no gui tools but we can use the powershell command available in windows server 2008r2 2012 2012r2 for our requirement.
You have a domain running with five domain controllers four running windows server 2008 r2 and one running windows server 2012. The windows server 2008 r2 domain or forest functional level can be lowered to windows server 2008 and no lower if and only if none of the active directory features that require a windows server 2008 r2 functional level has been activated. Get the current domain and forest functional levels using get adforest powersshell command we can determine our current forest functional level.
Trusted domain environments samba still has a number of limitations to its trusted domain support. Also right click on the active directory domains and trusts and select. There are some explanations with the functions up to windows server 2008 r2 and some on the differences between windows server 2008 r2 and windows server 2012.
Windows server 2012 r2 functional level. The current domain functional level is 2008r2 and the functional level is 2003. Active directory migration from windows 2003 to windows 2016.
As you can see the domain with a dfl of windows server 2012 r2 on the left has the additional redtrictedadmin option with mstsc exe while the domain with a dfl of windows 2008 does not.