Windows 2003 Forest Functional Level
Thought I'd post an informational post for folks who are moving an AD forest to Windows 2003 forest functional level (aka FFL2) as I realized today this piece of information might not be quite as well known as I might have thought. As an FYI, this change adds a number of attributes to the partial attribute set (aka the PAS or global catalog):
- 
Ms-DS-Trust-Forest-Trust-Info
 - 
Trust-Direction
 - 
Trust-Attributes
 - 
Trust-Type
 - 
Trust-Partner
 - 
Security Identifier
 - 
Ms-DS-Entry-Time-To-Die
 - 
MSMQ-Secured-Source
 - 
MSMQ-Multicast-Address
 - 
Print-Memory
 - 
Print-Rate
 - 
Print-Rate-Unit
 - 
MS-DRM-Identity-Certificate
 
This is done when you upgrade the forest functional level because at this point there are no Windows 2000 domain controllers in the forest and thus a change to the PAS will not force a GC resync. Recall that in Windows 2000, modifying the PAS caused every global catalog in the forest to replicate the global …