Affects product
- ●Active Directory / Windows Server 2012
Question or problem
Verify that the domain and forest functional level in Active Directory is Windows Server 2012 or higher.
Procedure-related prerequisites
- ●You need to be logged in as a domain administrator on a domain controller.
Instruction
- Test execution and verification:
- 1.Go to: Administrative Tools >> Active Directory Users and Computers.
- 2.In the left pane, right-click the root node for the domain. Then click Properties.
- 3.In the left span, select the root node and click on Properties in the context menu.
- The domain functional level and the forest functional level is Windows Server 2012 or higher.
- In case of failure:
- ●Raise the domain functional level.
- ●Raise the forest functional level.
- Solution - Raise the domain functional level
- 1.Go to: Administrative Tools >> Active Directory Users and Computers.
- 2.In the left pane, right-click the root node for the domain. Then click Raise domain functional level in the Action menu.
- 3.Select Windows 2012 or higher from the Select an available domain functional level dropdown box.
- 4.Click OK.
- Solution - Raise forest functional level
- 1.Go to: Administrative Tools >> Active Directory Domains and Trusts.
- 2.In the left pane, right-click the Active Directory Domains and Trusts node (top element in the tree). Then click Raise Forest Functional Level... in the Action menu.
- 3.Select Windows 2012 or higher from the Select an available domain functional level dropdown box.
- 4.Click OK.
HIGH – Kerberos authentication fails
- Raising the functional level cannot be undone.
- Check first if all Windows clients support the higher functional level.