# Raise Active Directory functional levels only after every domain controller earns the change

> The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication and recovery, remove incompatible controllers, and validate dependencies before raising either level.

- Canonical URL: https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-11T09:23:00+00:00
- Modified: 2026-08-11T14:12:11+00:00
- Last reviewed by DSE: 2026-08-11
- Resource type: Checklist
- DSE priority: Important
- Topics: Business Continuity, IT, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

The Windows Server 2025 AD DS functional level permits only Windows Server 2025 domain controllers. Inventory every domain and DC, prove replication and recovery, remove incompatible controllers, and validate dependencies before raising either level.

## Potentially affected

Active Directory forests and domains; Windows Server domain controllers; DNS, time, SYSVOL, directory-integrated applications, identity synchronization, backup, monitoring, and disaster-recovery processes.

## DSE recommendation

Capture the current forest and domain state, map the Microsoft interoperability matrix to every domain controller, resolve replication and SYSVOL issues, test directory recovery, and approve the functional-level change as a separate controlled event.

## Article

## Source facts: functional level governs domain-controller compatibility

Microsoft’s [AD DS functional-level documentation](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels) says forest and domain functional levels determine available Active Directory Domain Services capabilities and which Windows Server versions may run as domain controllers. They do not determine the operating systems allowed on ordinary member servers or workstations.

The current interoperability table draws a consequential boundary. At the Windows Server 2025 forest and domain functional level, Windows Server 2025 is the supported domain-controller operating system. Windows Server 2016, 2019, and 2022 domain controllers can coexist at the Windows Server 2016 functional level, and Microsoft notes that Windows Server 2019 and 2022 did not introduce newer functional levels of their own. A domain functional level may be higher than its forest functional level, but it cannot be lower than the forest functional level.

Microsoft identifies optional 32K database pages as a capability associated with the Windows Server 2025 domain functional level. That feature is not a reason to skip compatibility work: it has its own planning and enablement requirements. Microsoft also states that domains at the Windows Server 2016 functional level must use DFS Replication for SYSVOL. The documented PowerShell controls for raising levels are Set-ADDomainMode and Set-ADForestMode.

A domain-controller operating-system upgrade, schema preparation, adding or replacing a controller, and raising a functional level are related but separate changes. Microsoft’s domain-controller upgrade guidance generally favors adding newer servers as domain controllers, moving roles and dependencies, and demoting older controllers rather than treating the functional-level command as the migration itself.

## DSE recommendation: require an identity-service readiness packet

Build one packet for the forest and one for every domain before scheduling the change. The packet should be understandable to the person making the go/no-go decision and useful to the person responding if an application fails later.

- Inventory the topology. Record every domain, site, subnet, domain controller, global catalog, writable or read-only role, operating-system version, FSMO role, DNS role, replication connection, and time source. Reconcile the inventory with live directory data.

- Apply the compatibility gate. Compare every domain controller with Microsoft’s table for the intended level. Find offline, isolated, lab-connected, recovery, or forgotten controllers—not just servers that appear in the main management console.

- Prove directory health. Review replication across every naming context and site, DNS registration and resolution, SYSVOL and NETLOGON availability, DFSR state, time synchronization, event logs, backup status, and monitoring. Resolve unexplained errors before the change.

- Map consumers. Test applications and appliances that use LDAP, Kerberos, DNS, service accounts, directory searches, federation, certificate services, identity synchronization, or hard-coded domain-controller addresses. Record owners and representative workflows.

- Prove recovery. Verify system-state protection and perform a documented recovery exercise appropriate to the environment. Identify Directory Services Restore Mode access, authoritative and non-authoritative restore procedures, console access, media, and escalation ownership.

- Remove old controllers cleanly. Transfer or seize roles only through an approved plan, update dependent systems, demote supportedly, remove stale metadata when required, and confirm replication convergence before declaring the old version absent.

Schedule the domain-level and forest-level raises as explicit changes after the platform migration has stabilized. Capture the before-and-after values, operator, commands or console actions, timestamps, replication results, DNS and sign-in tests, application checks, and monitoring state. Avoid bundling the raise with controller replacement, network work, certificate changes, or identity-sync upgrades unless the combined recovery plan has been deliberately tested.

Finally, distinguish “eligible to raise” from “benefit approved.” The newest functional level should support a documented requirement or lifecycle plan. The safe outcome is a fully understood directory on compatible controllers with verified recovery—not a higher number displayed in an administration tool.

## Official references

- Microsoft Learn, [Active Directory Domain Services functional levels](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels), October 30, 2025.

- Microsoft Learn, [Upgrade domain controllers to a newer version of Windows Server](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers).

## Primary reference

- Name: Microsoft Learn: Active Directory Domain Services functional levels
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels
- Source publication date: 2025-10-30

## Citation and use

Preferred citation: “Raise Active Directory functional levels only after every domain controller earns the change,” DSE Security, https://update.dsesecurity.com/updates/active-directory-functional-level-upgrade-readiness/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
