PDIS
asked on
2016 Forest Level with XP Computers in domain
We are currently running at a Forest Level of 2008. I would like to upgrade us to a forest level of 2016. We currently have several computers that run Windows XP. Is there any compatibility issues I need to be concerned about?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
You selected an incorrect solution PDIS
If you already have a 2016 DC and XP machines, then you already have had to lower SMB to 1.0 which leaves your network at risk.Without enabling SMB 1.0 (bad idea) legacy devices will not pull GPOs. DFF and FFL does affect all operating systems, not just server OS'es
ASKER
So if we have XP machines currently on our network, which we do and I have no choice but to allow then if they are authenticating with our Server 2008 or Server 2016 DCs then we would have SMB 1.0 enabled already, correct? Are GPOs the only issue? Can we just create local GPOs for the XP machines and not enable SMB 1.0?
If your XP machines are already pulling GPOs from a 2016 DC, then you are probably OK. It isn't just GPOs that can be affected. However, if you have a 2008 DC now, you can't upgrade the Forest level or Domain level until it is gone. Server 2016 FFL and DFL require Server 2016 or Server 2019 DCs. No downlevel DCs are supported.
All that being said, XP is EOL (for a long time) and nothing at all is guaranteed. However, I have not seen any issues beyond the SMB version. I would recommend you upgrade your machines
Forgot to add, your Domains (all of them) must be at 2016 DFL to raise the Forest Level