Risks associated with raising the 2003 Forest and Domain level to 2003

Posted on 2007-08-04
Last Modified: 2013-11-05
I want to create a one way trust between 2 domains that are in seperate forests.  Does the Domain functional level and the Forest functional level need to be Windows Server 2003 to achieve this ?

Each domain has 2003 Domain Controllers, no NT4 servers and no Windows 2000 domain controllers.  The file servers / web servers are either Server 2000 or Server 2003.  

The clients in each domain are Windows 2000 or XP.  
Are there any risks attached to this ?  
Question by:tickleonthetum
    LVL 31

    Accepted Solution


    External trust between two domains can be always created, no need to raise domain or forest functional levels.
    If you do not have any NT4 or W2K DCs and you don't have any plans to add them to your network, you can safely raise domain and forest functional levels to benefit from improved replication and improved trust features.The only thing is that raising DFL or FFL is irreversible operation.


    LVL 70

    Assisted Solution

    as Toni says you don't need a specific functional level to create trusts, however iI would always advise raiseing the domain and forest functional level to the highest that can support whatever versions of Windows you are using - so if all of your DCs are Win2003 then use Windows 2003 levels - that way you get the most from the OS that you have paid for.

    Note that the limiations on which functional level you can use is depenant only on Domain Controllers, you can still raise the level to Windows 2003 even  if you have a Windows 2000 server - so long as it is not - and never will be, a Domain Controller.

    Author Comment

    thanks guys

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    I'm sure that every Windows systems administrator has written, or at least used, a batch or VBS login script at some point in their career, whether it is to map network drives, install printers, or set some user preferences.  No more! With Window…
    Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
    This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    730 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now