AD-DOM-01 - Domain functional level should be retrievable
Overviewβ
The domain functional level determines which Active Directory features are available in your domain. Higher functional levels unlock important security capabilities:
- Windows Server 2016+: Enables features like privileged access management (PAM), temporary group membership, and enhanced authentication policies
- Windows Server 2012 R2+: Provides access to claims-based authentication and compound authentication
- Security Posture: Running at lower functional levels means missing modern security features that protect against contemporary attack vectors
Security Recommendationβ
Aim to maintain your domain at the highest functional level supported by your domain controllers. Before raising the functional level:
- Verify all domain controllers are running a Windows Server version that supports the target level
- Test applications for compatibility with the higher functional level
- Plan the upgrade during a maintenance window
- Document the change and communicate to stakeholders
How the Test Worksβ
This test retrieves the current domain functional level from Active Directory and displays it along with basic domain information. The test is informational and helps you understand your current security capabilities.
Related Testsβ
Test-MtAdForestFunctionalLevel- Retrieves the forest functional levelTest-MtAdDomainControllerCount- Counts domain controllers in the domain
Related linksβ
- Microsoft Learn: Active Directory Domain Services functional levels
- ANSSI Active Directory checkpoints: Insufficient forest and domains functional levels
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DOM-01 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.Domain |
| PowerShell test | Test-MtAdDomainFunctionalLevel |
| Tags | AD, AD-DOM-01, AD.Domain |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdDomainFunctionalLevel.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdDomainFunctionalLevel.ps1


