Re: 2003 Domain Functional Level + trusts

Tech-Archive recommends: Fix windows errors by optimizing your registry



Also,
For DFL & FFL gotcha's, See: http://winserverteam.org.uk/blogs/austin/archive/2007/09/16/forest-functional-level-upgrade-notes.aspx

Regards,

Austin

"Austin Osuide" <austin@xxxxxxxxxxx> wrote in message news:ReBXi.5187$vA6.1414@xxxxxxxxxxxxxxxxxxxxxxxx
Hi,
Raising your Domain and Forest Functional level should have no impact on the trusts setup.
The thing I would consider though is the risk and complexity of the 2 changes and I'd get the migration out of the way before raising the functional level of the Domains.

But nothing says you can't do the raise before the migration.

Regards,

Austin
<digital.evasion@xxxxxxxxx> wrote in message news:1194230282.993635.268980@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi All,
I have been looking desperately trying to find some definitive answers
to our problem, but I never find anything specific.
First, the scenario:
We are in the process of integrating 4 separate networks (their own
domain + forest etc.) into one AD.
We have (I have changed the names for security) b.local, s.local,
m.local and t.local.
b.local is the head office, and all email lives here. Each other
office has its own file/print/AD.

Secondly, What's happening:
1. we are going to redesign the entire networks to one AD. B.local is
going to be the root domain. Other domains will be consolidated as
follows: s.local & m.local go into s.b.local, t.local goes into
b.b.local. both s.b.local and b.b.local are obviously child domains of
b.local.
2. Each Office/network has an EXTERNAL, NON TRANSITIVE trust to
b.local, and b.local has an EXTERNAL NON TRANSITIVE trust to each
office/network.
3. b.local, s.local, m.local and t.local (so ALL) are running 2000
MIXED Domain Functional Level
4. There are NO 2000 servers in any forest/domain/network anymore.

Finally, what's the Question:
Before migrating migrating users, domains etc. should/can we raise the
DFL to Windows 2000 Native or Windows 2003 without breaking/destroying
the trusts?
My understanding is that EXTERNAL Trusts don't have an impact on what
version AD you run, as its external.
My Colleague's and I cannot find a problem, fault with doing this. Are
looking in the wrong spot?
In addition should/can we raise the Forest Functional Level as well?

Many many many thanks in advance.

Lukas





.



Relevant Pages

  • Re: 2003 Domain Functional Level + trusts
    ... Raising your Domain and Forest Functional level should have no impact on the ... trusts setup. ... But nothing says you can't do the raise before the migration. ... In addition should/can we raise the Forest Functional Level as well? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forest/Domain Functionality Level and Trusts
    ... The further up the functional level you go - How to create a trust is the ... You can even create a trust with non-Microsoft directories ... but you need to be at 2003 Forest Functional level. ... > the AD's ability to create trusts with other NT 4.0 and Windows 2000 ADs? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... You need to do a forest prep to prepare the schema for R2 prior to adding an R2 Domain Controller. ... Anyway, you could be running into something odd when raising the forest functional level and even though it isn't required for R2, I will offer a command line mechanism to do it that will kick out an error message that can be used to work out the issue. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... LDP should have kicked out the error message as ... The domain functional level was Windows Server 2003. ... Server 2003 however the forest functional level is blank. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... Prior to the PDC failure replication worked perfectly and both DCs showed ... LDP should have kicked out the error message as ... The domain functional level was Windows Server 2003. ... Server 2003 however the forest functional level is blank. ...
    (microsoft.public.windows.server.active_directory)