Raise the funcitonal level of a domain

Posted on 2011-09-29
Last Modified: 2012-05-12
We have a domain with various servers from Windows Server 2000, 2003 & 2008 R2.

We have two domain controllers
Primary DC 2008 R2.  Secondary DC 2003 R2.

The 2000 Servers are simply holding legacy applications and are not Domain Controllers.  

Our functional level of the domain and forest is set to 2000 Native.  

Are there any issues with raising the funcitonal level of the domain and forest to 2003?
Question by:DHPBilcare
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
LVL 59

Accepted Solution

Darius Ghassem earned 250 total points
ID: 36814780
No issues at all

The only issue is that you will not be able to run any DC lower then Windows 2003 Server
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 250 total points
ID: 36814815
As dariusg said, no problem. If it's single forest single domain environment then you don't have to worry about Forest Functional Level. FFL can be at the same level as DFL. But if you have more domains, the be careful. FFL determines that other domain also must work in 2003 DFL!

The lowest OS on DC determines the highets possible DFL
The lowest DFL determines the highest possible FFL


Author Comment

ID: 36814861
Only other aspect to mention is that we are moving torwards a full domain trust with our sister company.  Two seperate domains.

Their functional level is 2003 native thus we have to riase ours to enable the two way trust.
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

LVL 59

Expert Comment

by:Darius Ghassem
ID: 36814866
That would be the best option

Author Comment

ID: 36814936
How long does the process take to raise?  

I know not best practice but are there any issues doing this while users are on the system?
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36815019
WHen you click "OK", it's done :] Your DFL is changed, up-and-running
The same for FFL

LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36815029
No, this action does not affect users workong in the system. That process is transparent.


Author Comment

ID: 36816899
Just to confirm one last point.

I have now raised the Functional level of our domain to 2003.  The forest is still set to 2000.

Will the trust now work?  

Just to clarify is there any issue to me simply raising our FFL to 2003 also?
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36817216
Yes, trust will work. If your domain(s) in the forest have no 2000 DCs, you can freely raise also FFL to 2003. It's the best choice to get two-way transitive trust between these 2 forests.
 That's new feature implemented in 2003 AD when you use FFL at 2003 level.

So, if you do not use 2000 DCs at all and do not plan to use them, raise FFL.

Before you will be able to establish trust, you need to configure DNS first. One of these options is required to get it working:
1) Define Conditional forwarders in your DNS management console for the domain from another forest
2) Create Stub zone in DNS for that zone

And of course make sure that you can reach that network from your environment :)


Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question