Understanding Domain and Forest Functional Levels
Updated: December 21, 2012
Applies To: Windows Server 2008, Windows Server 2008 R2, Windows Server 2012
Domain and forest functional levels
Domain and forest functional levels provide a way to enable domain-wide features or forest-wide features in your Active Directory Domain Services (AD DS) environment. Different levels of domain functionality and forest functionality are available, depending on your network environment.
If all the domain controllers in your domain or forest are running the latest version of Windows Server and the domain and forest functional level is set to highest value, all domain-wide features and forest-wide features are available. When your domain or forest contains domain controllers that run earlier versions of Windows Server, AD DS features are limited. For more information about how to enable domain-wide features or forest-wide features, see Raise the Domain Functional Level and Raise the Forest Functional Level.
Domain functional levels
Domain functionality enables features that affect the entire domain and that domain only. The following table lists the domain functional levels and their corresponding supported domain controllers:
| Domain functional level | Domain controller operating systems supported |
|---|---|
|
Windows Server 2003 |
Windows Server 2012 Windows Server 2008 R2 Windows Server 2008 Windows Server 2003 |
|
Windows Server 2008 |
Windows Server 2012 Windows Server 2008 R2 Windows Server 2008 |
|
Windows Server 2008 R2 |
Windows Server 2012 Windows Server 2008 R2 |
|
Windows Server 2012 |
Windows Server 2012 |
The following table describes the domain-wide features that are enabled for the domain functional levels.
| Domain functional level | Enabled features |
|---|---|
|
Windows 2000 native |
All default Active Directory features and the following features:
|
|
Windows Server 2003 |
All default Active Directory features, all features from the Windows 2000 native domain functional level, plus the following features:
|
|
Windows Server 2008 |
All default Active Directory features, all features from the Windows Server 2003 domain functional level, plus the following features:
|
|
Windows Server 2008 R2 |
All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus the following features:
|
|
Windows Server 2012 |
The KDC support for claims, compound authentication, and Kerberos armoring KDC administrative template policy has two settings ( Always provide claims and Fail unarmored authentication requests ) that require Windows Server 2012 domain functional level. For more information, see What's New in Kerberos Authentication. |
Forest functional levels
Forest functional levels enable features across all the domains in your forest. The following table lists the forest functional levels and their corresponding supported domain controllers.
| Forest functional level | Domain controller operating systems supported |
|---|---|
|
Windows Server 2003 |
Windows Server 2012 Windows Server 2008 R2 Windows Server 2008 Windows Server 2003 |
|
Windows Server 2008 |
Windows Server 2012 Windows Server 2008 R2 Windows Server 2008 |
|
Windows Server 2008 R2 (default) |
Windows Server 2012 Windows Server 2008 R2 |
|
Windows Server 2012 |
Windows Server 2012 |
The following table describes the forest-wide features that are enabled for forest functional levels.
| Forest functional level | Enabled features |
|---|---|
|
Windows Server 2003 |
All default Active Directory features, plus the following features:
|
|
Windows Server 2008 |
This functional level provides all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest, however, will operate at the Windows Server 2008 domain functional level by default. |
|
Windows Server 2008 R2 |
All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:
All domains that are subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default. If you plan to include only domain controllers that run Windows Server 2008 R2 in the entire forest, you might choose this forest functional level for administrative convenience. If you do, you will never have to raise the domain functional level for each domain that you create in the forest. |
|
Windows Server 2012 |
All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features. |
