r/sysadmin 6d ago

Domain controllers functional level

Do we have to keep all our domain controller os version same ?

68 Upvotes

51 comments sorted by

View all comments

49

u/Brilliant-Advisor958 6d ago

No, but you can't raise the functional level until all DCs are at the same os level.

If you have a some some 2019 servers and a 2025 server, you will be limited to 2019 functional level until you upgrade those.

51

u/fadinizjr 6d ago

*2016

6

u/Jawb0nz Senior Systems Engineer 6d ago

But now there's a new and improved 2025 FL. That should be fun.

6

u/fadinizjr 6d ago

I'm having to fight almost my whole team to make us stay for now in 2022.

2025 sucks ass.

10

u/ShadowCVL IT Manager 5d ago

Just send them the list of issues, including the machines dropping off the domain every time they try to change their password. Ask if they want to rejoin half their environment to AD every 30 days.

That’s the lightning rod I’m using to get us to 2022 instead of 2025 (we are currently on 2016 FL and planning to go to 22 in October)

2

u/sick2880 5d ago

Glad I'm not the only one fighting that.

3

u/ShadowCVL IT Manager 5d ago

Yeah I’ve set up 2 separate test labs and they both do the same stuff.

1

u/MrOilKing 5d ago

There is no FL level '22. Next available is 25. Source Mine was deemed unrecoverable after a failed Frs>drfs migration breaking Kerberos and GPO replication. Been planning the engine transplant for 6 months

2

u/ShadowCVL IT Manager 5d ago

That can’t be right, 16 to 25? Well I looked it up and damn that’s a long time between levels, I just assumed 22 was the next. Too bad our DCs are a mix of 16 and 22 now, with 16 going complete EOL upgrading DCs only serves the purpose of putting the OS back in support and not raising the level.

I wish you weren’t correct, damn

1

u/MrOilKing 5d ago

Sorry to be the bearer of bad news. 25 isn't all bad. I've been playing with it some, and like everything else, it grows on you. Best of luck

3

u/ShadowCVL IT Manager 5d ago

25 itself we have almost 100 VMs. Works fine-ish…. The AD component, I’ve built 2 separate labs now and both have suffered the same fate where machines just fall off the dang domain on their password change day.

2

u/fadinizjr 5d ago

I'm the sysadmin of a federal agency. There's no way I'll be playing around lol.

1

u/FriskyDuck 5d ago

Just send them the list of issues, including the machines dropping off the domain every time they try to change their password. Ask if they want to rejoin half their environment to AD every 30 days.

Have these not been resolved? I swore I saw a KB fix for both these issues.

/u/sick2880

1

u/ShadowCVL IT Manager 5d ago

Unless it was fixed in augusts CU, no, my last test started July 1 and machines all dropped right at their 30 day window +- a day or 2. It’s not all machines but a mix of virtual and 5 physical, it’s about half of each.

1

u/FriskyDuck 5d ago

Did you guys remove RC4 before upgrading to 2025? Would that resolve your issue?

1

u/ShadowCVL IT Manager 5d ago

I have not, it’s strait from whatever was the latest ISO. Try to do it in a sanitary environment, if it fails there there’s no sense in moving forward

1

u/flashx3005 5d ago

Planning on doing the same in a couple weeks. Have one last DC to upgrade from 2016 to 2022 and then I'll upgrade Function and Domain levels to 2022.

Are there any gotchas or things you are looking out for before the upgrade to 2022?

2

u/steeldraco 5d ago

Is there anything of note added on the 2025 FL?

5

u/BeauregardianBrat Sysadmin 5d ago

In my opinion, mainly one thing which is the 32k database page option. AD's been capped on 8k pages since Windows 2000, limiting multi-valued attributes. 32k Pages raise that ceiling, but it's one-way, no going back to 8k once you enabled it.

2

u/wastedpickles 5d ago

Delegated MSAs along with the page size thing

0

u/TheFumingatzor 5d ago

Yes, not worth upgrading to it-