{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/active-directory-functional-level-upgrade-readiness/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
        "slug": "active-directory-functional-level-upgrade-readiness",
        "url": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/active-directory-functional-level-upgrade-readiness/"
        },
        "title": "Raise Active Directory functional levels only after every domain controller earns the change",
        "summary": "The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication and recovery, remove incompatible controllers, and validate dependencies before raising either level.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-11T09:23:00+00:00",
        "modified_at": "2026-08-11T14:12:11+00:00",
        "reviewed_on": "2026-08-11",
        "reading_minutes": 3,
        "word_count": 609,
        "potentially_affected": "Active Directory forests and domains; Windows Server domain controllers; DNS, time, SYSVOL, directory-integrated applications, identity synchronization, backup, monitoring, and disaster-recovery processes.",
        "dse_recommendation": "Capture the current forest and domain state, map the Microsoft interoperability matrix to every domain controller, resolve replication and SYSVOL issues, test directory recovery, and approve the functional-level change as a separate controlled event.",
        "primary_source": {
            "name": "Microsoft Learn: Active Directory Domain Services functional levels",
            "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels",
            "published_on": "2025-10-30",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: functional level governs domain-controller compatibility</h2>\n<p>Microsoft’s <a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels\" target=\"_blank\" rel=\"noopener noreferrer\">AD DS functional-level documentation</a> says forest and domain functional levels determine available Active Directory Domain Services capabilities and which Windows Server versions may run as domain controllers. They do not determine the operating systems allowed on ordinary member servers or workstations.</p>\n<p>The current interoperability table draws a consequential boundary. At the Windows Server 2025 forest and domain functional level, Windows Server 2025 is the supported domain-controller operating system. Windows Server 2016, 2019, and 2022 domain controllers can coexist at the Windows Server 2016 functional level, and Microsoft notes that Windows Server 2019 and 2022 did not introduce newer functional levels of their own. A domain functional level may be higher than its forest functional level, but it cannot be lower than the forest functional level.</p>\n<p>Microsoft identifies optional 32K database pages as a capability associated with the Windows Server 2025 domain functional level. That feature is not a reason to skip compatibility work: it has its own planning and enablement requirements. Microsoft also states that domains at the Windows Server 2016 functional level must use DFS Replication for SYSVOL. The documented PowerShell controls for raising levels are <code>Set-ADDomainMode</code> and <code>Set-ADForestMode</code>.</p>\n<p>A domain-controller operating-system upgrade, schema preparation, adding or replacing a controller, and raising a functional level are related but separate changes. Microsoft’s domain-controller upgrade guidance generally favors adding newer servers as domain controllers, moving roles and dependencies, and demoting older controllers rather than treating the functional-level command as the migration itself.</p>\n\n<h2>DSE recommendation: require an identity-service readiness packet</h2>\n<p>Build one packet for the forest and one for every domain before scheduling the change. The packet should be understandable to the person making the go/no-go decision and useful to the person responding if an application fails later.</p>\n<ol>\n<li><strong>Inventory the topology.</strong> Record every domain, site, subnet, domain controller, global catalog, writable or read-only role, operating-system version, FSMO role, DNS role, replication connection, and time source. Reconcile the inventory with live directory data.</li>\n<li><strong>Apply the compatibility gate.</strong> Compare every domain controller with Microsoft’s table for the intended level. Find offline, isolated, lab-connected, recovery, or forgotten controllers—not just servers that appear in the main management console.</li>\n<li><strong>Prove directory health.</strong> Review replication across every naming context and site, DNS registration and resolution, SYSVOL and NETLOGON availability, DFSR state, time synchronization, event logs, backup status, and monitoring. Resolve unexplained errors before the change.</li>\n<li><strong>Map consumers.</strong> Test applications and appliances that use LDAP, Kerberos, DNS, service accounts, directory searches, federation, certificate services, identity synchronization, or hard-coded domain-controller addresses. Record owners and representative workflows.</li>\n<li><strong>Prove recovery.</strong> Verify system-state protection and perform a documented recovery exercise appropriate to the environment. Identify Directory Services Restore Mode access, authoritative and non-authoritative restore procedures, console access, media, and escalation ownership.</li>\n<li><strong>Remove old controllers cleanly.</strong> Transfer or seize roles only through an approved plan, update dependent systems, demote supportedly, remove stale metadata when required, and confirm replication convergence before declaring the old version absent.</li>\n</ol>\n<p>Schedule the domain-level and forest-level raises as explicit changes after the platform migration has stabilized. Capture the before-and-after values, operator, commands or console actions, timestamps, replication results, DNS and sign-in tests, application checks, and monitoring state. Avoid bundling the raise with controller replacement, network work, certificate changes, or identity-sync upgrades unless the combined recovery plan has been deliberately tested.</p>\n<p>Finally, distinguish “eligible to raise” from “benefit approved.” The newest functional level should support a documented requirement or lifecycle plan. The safe outcome is a fully understood directory on compatible controllers with verified recovery—not a higher number displayed in an administration tool.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>Microsoft Learn, <a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Active Directory Domain Services functional levels</em></a>, October 30, 2025.</li>\n<li>Microsoft Learn, <a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Upgrade domain controllers to a newer version of Windows Server</em></a>.</li>\n</ul>",
        "content_text": "Source facts: functional level governs domain-controller compatibility\nMicrosoft’s AD DS functional-level documentation says forest and domain functional levels determine available Active Directory Domain Services capabilities and which Windows Server versions may run as domain controllers. They do not determine the operating systems allowed on ordinary member servers or workstations.\nThe current interoperability table draws a consequential boundary. At the Windows Server 2025 forest and domain functional level, Windows Server 2025 is the supported domain-controller operating system. Windows Server 2016, 2019, and 2022 domain controllers can coexist at the Windows Server 2016 functional level, and Microsoft notes that Windows Server 2019 and 2022 did not introduce newer functional levels of their own. A domain functional level may be higher than its forest functional level, but it cannot be lower than the forest functional level.\nMicrosoft identifies optional 32K database pages as a capability associated with the Windows Server 2025 domain functional level. That feature is not a reason to skip compatibility work: it has its own planning and enablement requirements. Microsoft also states that domains at the Windows Server 2016 functional level must use DFS Replication for SYSVOL. The documented PowerShell controls for raising levels are Set-ADDomainMode and Set-ADForestMode.\nA domain-controller operating-system upgrade, schema preparation, adding or replacing a controller, and raising a functional level are related but separate changes. Microsoft’s domain-controller upgrade guidance generally favors adding newer servers as domain controllers, moving roles and dependencies, and demoting older controllers rather than treating the functional-level command as the migration itself.\n\nDSE recommendation: require an identity-service readiness packet\nBuild one packet for the forest and one for every domain before scheduling the change. The packet should be understandable to the person making the go/no-go decision and useful to the person responding if an application fails later.\n\nInventory the topology. Record every domain, site, subnet, domain controller, global catalog, writable or read-only role, operating-system version, FSMO role, DNS role, replication connection, and time source. Reconcile the inventory with live directory data.\nApply the compatibility gate. Compare every domain controller with Microsoft’s table for the intended level. Find offline, isolated, lab-connected, recovery, or forgotten controllers—not just servers that appear in the main management console.\nProve directory health. Review replication across every naming context and site, DNS registration and resolution, SYSVOL and NETLOGON availability, DFSR state, time synchronization, event logs, backup status, and monitoring. Resolve unexplained errors before the change.\nMap consumers. Test applications and appliances that use LDAP, Kerberos, DNS, service accounts, directory searches, federation, certificate services, identity synchronization, or hard-coded domain-controller addresses. Record owners and representative workflows.\nProve recovery. Verify system-state protection and perform a documented recovery exercise appropriate to the environment. Identify Directory Services Restore Mode access, authoritative and non-authoritative restore procedures, console access, media, and escalation ownership.\nRemove old controllers cleanly. Transfer or seize roles only through an approved plan, update dependent systems, demote supportedly, remove stale metadata when required, and confirm replication convergence before declaring the old version absent.\n\nSchedule the domain-level and forest-level raises as explicit changes after the platform migration has stabilized. Capture the before-and-after values, operator, commands or console actions, timestamps, replication results, DNS and sign-in tests, application checks, and monitoring state. Avoid bundling the raise with controller replacement, network work, certificate changes, or identity-sync upgrades unless the combined recovery plan has been deliberately tested.\nFinally, distinguish “eligible to raise” from “benefit approved.” The newest functional level should support a documented requirement or lifecycle plan. The safe outcome is a fully understood directory on compatible controllers with verified recovery—not a higher number displayed in an administration tool.\n\nOfficial references\n\nMicrosoft Learn, Active Directory Domain Services functional levels, October 30, 2025.\nMicrosoft Learn, Upgrade domain controllers to a newer version of Windows Server.",
        "content_markdown": "## Source facts: functional level governs domain-controller compatibility\n\nMicrosoft’s [AD DS functional-level documentation](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels) says forest and domain functional levels determine available Active Directory Domain Services capabilities and which Windows Server versions may run as domain controllers. They do not determine the operating systems allowed on ordinary member servers or workstations.\n\nThe current interoperability table draws a consequential boundary. At the Windows Server 2025 forest and domain functional level, Windows Server 2025 is the supported domain-controller operating system. Windows Server 2016, 2019, and 2022 domain controllers can coexist at the Windows Server 2016 functional level, and Microsoft notes that Windows Server 2019 and 2022 did not introduce newer functional levels of their own. A domain functional level may be higher than its forest functional level, but it cannot be lower than the forest functional level.\n\nMicrosoft identifies optional 32K database pages as a capability associated with the Windows Server 2025 domain functional level. That feature is not a reason to skip compatibility work: it has its own planning and enablement requirements. Microsoft also states that domains at the Windows Server 2016 functional level must use DFS Replication for SYSVOL. The documented PowerShell controls for raising levels are Set-ADDomainMode and Set-ADForestMode.\n\nA domain-controller operating-system upgrade, schema preparation, adding or replacing a controller, and raising a functional level are related but separate changes. Microsoft’s domain-controller upgrade guidance generally favors adding newer servers as domain controllers, moving roles and dependencies, and demoting older controllers rather than treating the functional-level command as the migration itself.\n\n## DSE recommendation: require an identity-service readiness packet\n\nBuild one packet for the forest and one for every domain before scheduling the change. The packet should be understandable to the person making the go/no-go decision and useful to the person responding if an application fails later.\n\n- Inventory the topology. Record every domain, site, subnet, domain controller, global catalog, writable or read-only role, operating-system version, FSMO role, DNS role, replication connection, and time source. Reconcile the inventory with live directory data.\n\n- Apply the compatibility gate. Compare every domain controller with Microsoft’s table for the intended level. Find offline, isolated, lab-connected, recovery, or forgotten controllers—not just servers that appear in the main management console.\n\n- Prove directory health. Review replication across every naming context and site, DNS registration and resolution, SYSVOL and NETLOGON availability, DFSR state, time synchronization, event logs, backup status, and monitoring. Resolve unexplained errors before the change.\n\n- Map consumers. Test applications and appliances that use LDAP, Kerberos, DNS, service accounts, directory searches, federation, certificate services, identity synchronization, or hard-coded domain-controller addresses. Record owners and representative workflows.\n\n- Prove recovery. Verify system-state protection and perform a documented recovery exercise appropriate to the environment. Identify Directory Services Restore Mode access, authoritative and non-authoritative restore procedures, console access, media, and escalation ownership.\n\n- Remove old controllers cleanly. Transfer or seize roles only through an approved plan, update dependent systems, demote supportedly, remove stale metadata when required, and confirm replication convergence before declaring the old version absent.\n\nSchedule the domain-level and forest-level raises as explicit changes after the platform migration has stabilized. Capture the before-and-after values, operator, commands or console actions, timestamps, replication results, DNS and sign-in tests, application checks, and monitoring state. Avoid bundling the raise with controller replacement, network work, certificate changes, or identity-sync upgrades unless the combined recovery plan has been deliberately tested.\n\nFinally, distinguish “eligible to raise” from “benefit approved.” The newest functional level should support a documented requirement or lifecycle plan. The safe outcome is a fully understood directory on compatible controllers with verified recovery—not a higher number displayed in an administration tool.\n\n## Official references\n\n- Microsoft Learn, [Active Directory Domain Services functional levels](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels), October 30, 2025.\n\n- Microsoft Learn, [Upgrade domain controllers to a newer version of Windows Server](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
                "url": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-11"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Raise Active Directory functional levels only after every domain controller earns the change",
                        "item": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/#article",
                "identifier": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
                "url": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/",
                "headline": "Raise Active Directory functional levels only after every domain controller earns the change",
                "description": "The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication…",
                "abstract": "The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication and recovery, remove incompatible controllers, and validate dependencies before raising either level.",
                "articleBody": "Source facts: functional level governs domain-controller compatibility\nMicrosoft’s AD DS functional-level documentation says forest and domain functional levels determine available Active Directory Domain Services capabilities and which Windows Server versions may run as domain controllers. They do not determine the operating systems allowed on ordinary member servers or workstations.\nThe current interoperability table draws a consequential boundary. At the Windows Server 2025 forest and domain functional level, Windows Server 2025 is the supported domain-controller operating system. Windows Server 2016, 2019, and 2022 domain controllers can coexist at the Windows Server 2016 functional level, and Microsoft notes that Windows Server 2019 and 2022 did not introduce newer functional levels of their own. A domain functional level may be higher than its forest functional level, but it cannot be lower than the forest functional level.\nMicrosoft identifies optional 32K database pages as a capability associated with the Windows Server 2025 domain functional level. That feature is not a reason to skip compatibility work: it has its own planning and enablement requirements. Microsoft also states that domains at the Windows Server 2016 functional level must use DFS Replication for SYSVOL. The documented PowerShell controls for raising levels are Set-ADDomainMode and Set-ADForestMode.\nA domain-controller operating-system upgrade, schema preparation, adding or replacing a controller, and raising a functional level are related but separate changes. Microsoft’s domain-controller upgrade guidance generally favors adding newer servers as domain controllers, moving roles and dependencies, and demoting older controllers rather than treating the functional-level command as the migration itself.\n\nDSE recommendation: require an identity-service readiness packet\nBuild one packet for the forest and one for every domain before scheduling the change. The packet should be understandable to the person making the go/no-go decision and useful to the person responding if an application fails later.\n\nInventory the topology. Record every domain, site, subnet, domain controller, global catalog, writable or read-only role, operating-system version, FSMO role, DNS role, replication connection, and time source. Reconcile the inventory with live directory data.\nApply the compatibility gate. Compare every domain controller with Microsoft’s table for the intended level. Find offline, isolated, lab-connected, recovery, or forgotten controllers—not just servers that appear in the main management console.\nProve directory health. Review replication across every naming context and site, DNS registration and resolution, SYSVOL and NETLOGON availability, DFSR state, time synchronization, event logs, backup status, and monitoring. Resolve unexplained errors before the change.\nMap consumers. Test applications and appliances that use LDAP, Kerberos, DNS, service accounts, directory searches, federation, certificate services, identity synchronization, or hard-coded domain-controller addresses. Record owners and representative workflows.\nProve recovery. Verify system-state protection and perform a documented recovery exercise appropriate to the environment. Identify Directory Services Restore Mode access, authoritative and non-authoritative restore procedures, console access, media, and escalation ownership.\nRemove old controllers cleanly. Transfer or seize roles only through an approved plan, update dependent systems, demote supportedly, remove stale metadata when required, and confirm replication convergence before declaring the old version absent.\n\nSchedule the domain-level and forest-level raises as explicit changes after the platform migration has stabilized. Capture the before-and-after values, operator, commands or console actions, timestamps, replication results, DNS and sign-in tests, application checks, and monitoring state. Avoid bundling the raise with controller replacement, network work, certificate changes, or identity-sync upgrades unless the combined recovery plan has been deliberately tested.\nFinally, distinguish “eligible to raise” from “benefit approved.” The newest functional level should support a documented requirement or lifecycle plan. The safe outcome is a fully understood directory on compatible controllers with verified recovery—not a higher number displayed in an administration tool.\n\nOfficial references\n\nMicrosoft Learn, Active Directory Domain Services functional levels, October 30, 2025.\nMicrosoft Learn, Upgrade domain controllers to a newer version of Windows Server.",
                "datePublished": "2026-08-11T09:23:00+00:00",
                "dateModified": "2026-08-11T14:12:11+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Raise Active Directory functional levels only after every domain controller earns the change"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 609,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Learn: Active Directory Domain Services functional levels",
                    "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels",
                    "datePublished": "2025-10-30"
                }
            }
        ]
    }
}