What are the necessary conditions and permissions required to raise domain or forest functional levels? For the toolbar, press ALT+F10 (PC) or ALT+FN+F10 (Mac).
Q What are the necessary conditions and permissions required to raise domain or forest functional levels?
Ans: In the active directory the functional level of a forest or domain functional methods are raised to enable or make available the advanced features for the users..To view and modify the current domain and forest functional level settings we use the Lightweight Directory Access Protocol (LDAP) tools.The tools such are Ldp.exe and Adsiedit.msc .
The following conditions and permissions are require for the Domain functional level settings:Firstly let's know about the Domain functional level settings. This setting are used to specify whether this domain support the new security and features that are added in Windows 2000 and the Windows server 2003. the The naming context (NC) head for the domain msDS-Behavior-Version attribute are DC=com, , DC=corp,DC=contoso.The value of the following attributes are set:
The following conditions and permissions are require for
the Forest functional level settings: In the
Configuration naming context (NC) i.e CN=Configuration,
CN=Partitions,DC=ForestRootDomain.
for , the msDS-Behavior-Version attribute object is on
the CN=Partitions.The following value of the attribute are set as
follows:
Here , we have to note that when we increase the msDS-Behavior-Version attribute from 0 value to 1 by using the Adsiedit.msc , we receive the following error message:
Illegal modify operation. Some aspect of the modification is not permitted.
After that to edit the the functional level ue use Lightweight Directory Access Protocol (LDAP) tools and then click ok to continue.The domain head and the partitions container attribute are correctly increased.If any error message are report by the Ldp.exe file,then safely we have to ignore the error message.To verify the attribute that the level increase was successful , we have to refresh the attribute list and then we have to check the current setting.This error message can be occur after that we have to perform the level increase on the authoritative FSMO,yet the changes has not done then replicated to the local domain controller.
THANKS, i think this will give you a better intuition about your question.If you have any doubt feel free to ask in the comment section.
Get Answers For Free
Most questions answered within 1 hours.