Risks of raising domain/forest functional level from 2003 mixed to 2008 native

We are just about to complete the process of replacing all of our Windows 2003 domain controllers with Windows 2008 R2 domain controllers. Once completed, we would then like to raise the domain functional level (of our forest and the domains) from 2003 mixed mode to 2008 native mode.

Our Exchange environment is already on 2010. We have a number of other member servers still running Windows 2003. We also have some Intranet servers and other .NET/IIS applications that us AD for authentication. Finally, our public-facing WEB servers uses the IIS shared config feature and pull configurations from a NAS appliance, again using AD for authentication.

My question is as follows; are there any known issues or risks to be aware of with our servers, particularly the public-facing WEB servers, if/when we raise the Forest/Domain levels to 2008 native mode?  Any specific risks, other than the normal risk you take when doing an upgrade?

Thank you.

January 27th, 2011 10:35pm

Raising the functional level has nothing to do with member server,even though DFL is windows 2008, you can still run member server of lower OS version(2000/2003) , that means once you have your DFL to windows 2008, you cant have dc's running on windows 2000 or 2003,so application dependent on them for authentication will not work, but i have never heard of any application.

So,if you have any doubt, you can test in a lab or take system state back up before raising the DFL.

DFL once raised can't be reverted back & it can only be reverted by  restoring to previous backup.

 

Free Windows Admin Tool Kit Click here and download it now
January 28th, 2011 4:51am

Hello,

raising the functional levels have only effect on DCs, not on member servers. The only "risk" is that you can't go back to Windows server 2003 anymore.

To be sure create a lab with the major server roles you have or where you have thoughts it can result in trouble and test it there first, which btw. should be always done before doing such steps in production domains.

January 28th, 2011 7:01am

I will caution, you our SAN had to be upgraded prior to us pulling the plug and moving forward.  You should be able to bring up a virtual SAN to simulate your environment.  Also (Unrelated to AD but the o/s), check your backup and AV and verify that they are certified for 2008 R2, we have had a lot issues with vendors covering this.

--
Paul Bergson
MVP - Directory Services
MCITP: Enterprise Administrator
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com    Twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson

Please no e-mails, any questions should be posted in the NewsGroup. This
posting is provided "AS IS" with no warranties, and confers no rights.

Free Windows Admin Tool Kit Click here and download it now
January 28th, 2011 1:15pm

The key thing is moving the FSMO roles to the 2008 R2 DCs, in particular the PDC emulator introduces new objects.  If you upgrade to Windows 2008 R2 domain/forest then you can't use 2003 DCs anymore.

Computer browser service is disabled by default in Windows 2008 R2

Backup software need to be verified as working with 2008 R2 as well.  Other than that there is minimumal risk

Transitioning a Windows 2003 Domain to Windows 2008 R2
http://networkadminkb.com/Shared%20Documents/Transitioning%20a%20Windows%202003%20Domain%20to%20Windows%202008%20R2.aspx

 

January 31st, 2011 3:01am

I will caution, you our SAN had to be upgraded prior to us pulling the plug and moving forward.  You should be able to bring up a virtual SAN to simulate your environment.  Also (Unrelated to AD but the o/s), check your backup and AV and verify that they are certified for 2008 R2, we have had a lot issues with vendors covering this.

--
Paul Bergson
MVP - Directory Services
MCITP: Enterprise Administrator
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com    Twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson

Please no e-mails, any questions should be posted in the NewsGroup. This
posting is provided "AS IS" with no warranties, and confers no rights.

Hi,

Do you need to restart any Domain Controllers or Exchange Servers after the Domain/Forest Functionality level from 2003 to 2008R2 ?

Free Windows Admin Tool Kit Click here and download it now
August 5th, 2015 2:38am

Hi,

Do you need to restart any Domain Controllers or Exchange Servers after the Domain/Forest Functionality level from 2003 to 20

August 5th, 2015 2:49am

Hi,

Do you need to restart any Domain Controllers or Exchange Servers after the Domain/Forest Functionality level from 2003 to 20

Free Windows Admin Tool Kit Click here and download it now
August 5th, 2015 3:26am


Thanks Branko, what about trasnferring or migrating the FRS into another Domain Controller ?

https://msdn.microsoft.com/en-us/library/windows/desktop/ff384840%28v=vs.85%29.aspx

because from that website it says that it is obs

August 5th, 2015 3:46am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics