Harry1980 Posted January 21, 2019 Posted January 21, 2019 I am trying to setup password policies through active directory administrative centre and realised the New and Delete options are greyed out. After doing some research it could be because of my domain and forest functional level. We have 2 servers, the domain controller is a Server 2012 (R2) and the other Server is 2008 (R2). I have checked the Forest and Domain Functional level on both servers and it is set to Windows Server 2003. I want to raise the levels on both servers so that I can have access to the facilities on ADAC. What do I do? Do I just raise the level on the Server 2008 R2 to its highest level which is Windows Server 2008 R2 and do the same to the Server 2012 R2? Or do I need to do it on server 2012 first? I am guessing I should not raise the Forest/domain functional level do Windows Server 2012 as Server 2008 will not support it. Is there precautions I need to take? If there is any issues can I just roll back etc, does the server need a reboot after I have raised the level? Thanks in advance.
HPlum78 Posted January 21, 2019 Posted January 21, 2019 https://support.microsoft.com/en-gb/help/322692/how-to-raise-active-directory-domain-and-forest-functional-levels Should guide you on your way and means that I don't have to type it all in :-p Think it covers your questions.
Harry1980 Posted January 23, 2019 Author Posted January 23, 2019 Thanks for that. I think I got my head around how to raise the domain and forest functional levels. As we have 2 DC on the network, 1 on Server 2008 R2 and the other 1 on Server 2012 does it matter which DC domain functional level I raise first? would that replicate to the other DC or do I have to manually raise the domain functional level on both DC? Once that's done I will raise the forest functional level.
Linfit Posted January 23, 2019 Posted January 23, 2019 It doesn't matter which DC you do it on, it will replicate to both. You will only be able to get as high as 2008 functional level though as long as you have a 2008 DC. 1
Harry1980 Posted January 23, 2019 Author Posted January 23, 2019 Thank you for that Linfit. I am planning to raise it to Windows Server 2008 R2. If I do it now it shouldn't affect the network users should it?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now