Windows 2003 Forest Functional Level
Thought I'd post an informational post for folks who are moving an AD forest to Windows 2003 forest functional level (aka FFL2) as I realized today this piece of information might not be quite as well known as I might have thought. As an FYI, this change adds a number of attributes to the partial attribute set (aka the PAS or global catalog):
-
Ms-DS-Trust-Forest-Trust-Info
-
Trust-Direction
-
Trust-Attributes
-
Trust-Type
-
Trust-Partner
-
Security Identifier
-
Ms-DS-Entry-Time-To-Die
-
MSMQ-Secured-Source
-
MSMQ-Multicast-Address
-
Print-Memory
-
Print-Rate
-
Print-Rate-Unit
-
MS-DRM-Identity-Certificate
This is done when you upgrade the forest functional level because at this point there are no Windows 2000 domain controllers in the forest and thus a change to the PAS will not force a GC resync. Recall that in Windows 2000, modifying the PAS caused every global catalog in the forest to replicate the global …