| Previous | Next |
| ERROR_DS_DOMAIN_VERSION_TOO_HIGH | ERROR_DS_DOMAIN_VERSION_TOO_LOW |
ERROR_DS_FOREST_VERSION_TOO_LOW
The candidate DC requires a newer forest or configuration-set behavior level
Functional-level compatibility has both an upper and a lower side. A newer directory-service build can stop supporting deployment into an older forest behavior level even though it understands newer features. Windows Server release requirements therefore need to be checked before promotion, not inferred from the ability of existing clients to use LDAP or Kerberos.
Inventory all domain controllers and verify that the environment is ready to raise functional levels through supported tools. Raising the forest level can enable behavior that older DCs cannot host, so remove or upgrade incompatible domain controllers first and ensure replication is healthy. For AD LDS, inspect the configuration-set behavior version and every participating instance before changing the level.
What to inspect
- Read the existing forest or AD LDS configuration-set behavior level.
- Inventory directory servers that would be affected by a level increase.
- Resolve replication and obsolete-server metadata before raising the level.
References
- Microsoft: AD DS functional levels
- Microsoft: raise domain and forest functional levels
- MS-ADTS: forest functional level
Looking for a different code? Search another status or error code.