What does Windows error code 8563 (ERROR_DS_FOREST_VERSION_TOO_HIGH) mean?

 
Previous Next
ERROR_DS_SAM_INIT_FAILURE_CONSOLE ERROR_DS_DOMAIN_VERSION_TOO_HIGH

ERROR_DS_FOREST_VERSION_TOO_HIGH

The candidate server is too old for the current forest functional level

MS-ADTS defines the forest functional level as a lower bound on the directory-server capability permitted in the forest. A DC advertises its highest supported behavior level through msDS-Behavior-Version. If the forest value exceeds that capability, the server cannot become a compatible DC or AD LDS replica for the configuration set involved.

Read the current forest mode and identify the exact operating-system build of the candidate. This is not corrected by lowering a random DSA attribute or changing compatibility mode on the application. Either use a server version that supports the forest level or, only where Microsoft documents a supported rollback path, change the functional level through supported administration tools after evaluating enabled features and every DC in the forest.

What to inspect

  • Compare ForestMode with the candidate server version and DSA behavior capability.
  • Check whether the error refers to AD DS forest or an AD LDS configuration set.
  • Do not edit msDS-Behavior-Version directly to make an older server appear compatible.

References


Looking for a different code? Search another status or error code.