Windows 10: Raising the windows domain and forest issues?

Discus and support Raising the windows domain and forest issues? in Windows 10 Installation and Upgrade to solve the problem; hi, I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2. That went off without any... Discussion in 'Windows 10 Installation and Upgrade' started by changari, May 14, 2019.

  1. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====Need to investigate more and why this post


    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW

    :)
     
    changari, May 14, 2019
    #1

  2. Performing a Forest Restore in Case of Forest Function Level Upgrade Failure

    Hello All,

    We have a small business client that is currently looking to finally upgrade their infrastructure. Part of this process will include upgrading their existing functional forest level from server 2000 NT to server
    2003, in order to create a trust with a newer domain that we are building for them. The newer domain will have servers that are only server 2008 and newer (eventually only server 2012 or newer) and will be disconnected from the old domain once all migration
    occurs. We have a plan in place to complete this properly, but there is one piece of the puzzle that I have yet to truly figure out.

    The process to raise a Forest/Domain functional level is beyond easy, but I have not yet hammered down the process of performing a Forest/Domain Restore. I realize that a restore is literally the only way to
    recover from a forest functional level upgrade failure. I realize these failures are beyond rare, but I would rather be safe than sorry. Could anyone point me to a straightforward guide on how to perform a Forest/Domain Restore on a pair of server 2003 domain
    controllers?

    As an important secondary question, one of my superiors is having a hard time believing the fact that simply taking a full backup of both domain controllers and restoring using those backups alone would not
    restore the domain to working condition. Could anyone explain why you have to complete all of these forest restore steps instead of being able to just restore from a full backup on both DC's?
     
    jelliott77, May 14, 2019
    #2
  3. Hub-Site Win User
    root forest -Trust

    Hi all,

    hope someone can shed some light on this issue. In our environment we have Windows Server 2003 DC on domain (A). and DC 2012 R2 Domain (B). these two are not same forest root.

    we setup one-way Trust (Type) Forest trust transitive= Domain B (2012 R2 DC) trusted Domain A (2003 DC)=

    -Direction of trust- Outgoing

    -Transitivity of trust- forest transitive

    -Validated successful.

    -Name suffix Routing setup for Domain.local B forest.

    -authentication Forest wide - forest wide authentication

    validated = passed (no problem here)

    adding users to domain B group = failed error stated (some of the object names cannot be shown in their user-friendly name form , this can happen if the object is from an external domain and that domain is not available to translate the object name)



    this happened after selected some users from domain A, which mean I did able browsing on domain-A of AD.

    If we tried two way trust then everything seemed OK, we were able successfully added some users. so no issue on two-way trust.

    if two way-trust is fine, that's rule out DNS, right?

    thank you every much in advance.
     
    Hub-Site, May 14, 2019
    #3
  4. Raising the windows domain and forest issues?

    Windows Server 2016 - Join a child domain to a remote forest

    I have 2 instances of Server 2016 Data Center running on virtual box and both of these OS are on separate networks. The reason i use separate networks is because i want to test if the child at a remote site is able to join a forest located at another site/network
    with different internal IP address.

    I want to be able to contact my forest located at a remote network from a separate network so that once i establish a child domain on my server 02 machine which is located at a separate network, i am able to make a child domain controller and part of the
    forest were the root domain is.

    Is that possible or does the child domain have to be in the same network as the forest it wishes to connect to?

    I have made 2 sites. Site A and Site B. The sites are set up and so is the subnet part. I have also created a direct IP link to it.

    Can you please offer me technical support. I know sometimes its paid but i don't mind going through that just to resolve the problem
     
    RaghavSood, May 14, 2019
    #4
Thema:

Raising the windows domain and forest issues?

Loading...
  1. Raising the windows domain and forest issues? - Similar Threads - Raising domain forest

  2. Issue with domain login

    in Windows 10 Gaming
    Issue with domain login: Very strange problem, I got called from a user that they couldn't access their active directory account, I logged in remotely with her account no problem, I reset her password and she still couldn't login I thought it was a corrupt use profile, I went out to site and when I...
  3. Issue with domain login

    in Windows 10 Software and Apps
    Issue with domain login: Very strange problem, I got called from a user that they couldn't access their active directory account, I logged in remotely with her account no problem, I reset her password and she still couldn't login I thought it was a corrupt use profile, I went out to site and when I...
  4. Windows credential issues on a local domain

    in Windows 10 Network and Sharing
    Windows credential issues on a local domain: Novice sysadmin here on a locally hosted domain. We're having an issue with windows credentials where, my endpoints have manually created credentials to access a network share hosted from a local server which contains the front end to an SQL server we run on MS Access,...
  5. What are the Impacts of Upgrading the Domain and Forest Functional Level in a Production AD...

    in Windows 10 Gaming
    What are the Impacts of Upgrading the Domain and Forest Functional Level in a Production AD...: Dear All,I'd like to clarify the following concerns with you. We have a customer who has the following infrastructure and they want to raise the forest and domain functional levels in the Active Directory environment. Hence, we are seeking your expertise to clarify the...
  6. What are the Impacts of Upgrading the Domain and Forest Functional Level in a Production AD...

    in Windows 10 Software and Apps
    What are the Impacts of Upgrading the Domain and Forest Functional Level in a Production AD...: Dear All,I'd like to clarify the following concerns with you. We have a customer who has the following infrastructure and they want to raise the forest and domain functional levels in the Active Directory environment. Hence, we are seeking your expertise to clarify the...
  7. Windows 11 22H2 Domain Joined and the minimum Domain Controllers domain and forest...

    in Windows 10 Gaming
    Windows 11 22H2 Domain Joined and the minimum Domain Controllers domain and forest...: I am writing to seek clarification and guidance regarding the domain joining requirements and the minimum domain controllers domain and forest functional level supported by Windows 11 22H2.Our organization is currently planning an upgrade to Windows 11 22H2 for our client...
  8. Windows 11 22H2 Domain Joined and the minimum Domain Controllers domain and forest...

    in Windows 10 Software and Apps
    Windows 11 22H2 Domain Joined and the minimum Domain Controllers domain and forest...: I am writing to seek clarification and guidance regarding the domain joining requirements and the minimum domain controllers domain and forest functional level supported by Windows 11 22H2.Our organization is currently planning an upgrade to Windows 11 22H2 for our client...
  9. Macrium Reflect issue with point to raise window mode

    in Windows 10 Backup and Restore
    Macrium Reflect issue with point to raise window mode: I have my Windows10 configured to point-to-raise instead of click to raise windows and when I am in Macrium, I cannot select the disk to clone to. When I move the mouse, the window underneath the disks-to-clone selection becomes active. It just started doing that with this...
  10. Issue raised for non working of Headphones

    in Windows 10 Customization
    Issue raised for non working of Headphones: Dear sir/mam, I am shivam sahani from varanasi, UP, India There is a problem related to Headphone, i actually so disturb because of Headphone unworking... whenever i plugin Headphone in my Laptop there is inside and outside, both side the volume comes so sometimes it's too...