Solved

Windows 2003 Server -- raise "forest level" error ?

Posted on 2014-12-10
3
526 Views
Last Modified: 2014-12-23
I logged into my Windows 2003 Standard 32bit Server "domain controller" as administrator on the DOMAIN (not local PC), tried to raise the FOREST FUNCTIONAL LEVEL from 2000 to 2003 so it matches the server's DOMAIN FUNCTIONAL LEVEL, and got a "you do not have sufficient privilege to raise the forest functional level" error.

Anyone have possible solutions ?
0
Comment
Question by:finance_teacher
  • 2
3 Comments
 
LVL 33

Accepted Solution

by:
it_saige earned 500 total points
ID: 40491635
Make sure that the user you used is -
a member of either the Domain Admins group (in the forest root domain) or the Enterprise Admins group in Active Directory
Source

-saige-
0
 

Author Comment

by:finance_teacher
ID: 40491712
Steps
 1. logged into DC as administrator on the DOMAIN (not local PC)
 2. opened AD User/Groups
 3. tried to add the below per your suggestion
 4. get "you do not have permission to modify the group ROOT/TLD/Users/Enterprise Admins" ... error

How can I find out which administrator type account
can grant my administrator account access to this ?
0
 
LVL 33

Assisted Solution

by:it_saige
it_saige earned 500 total points
ID: 40491733
Look at your users group memberships:

Example -Capture.JPG
Or the members of the Enterprise Admins group:

Example -Capture.JPG
-saige-
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question