Skip to main content
Version: 2.2.1-preview

AD-FOR-01 - Forest functional level should be retrievable

Overview​

The forest functional level determines which Active Directory features are available across all domains in the forest. Higher functional levels unlock important forest-wide security capabilities:

  • Windows Server 2016+: Enables features like privileged access management (PAM) across the forest
  • Windows Server 2012 R2+: Provides access to forest-wide authentication policies and silos
  • Global Features: Some features require forest-wide consistency to function
  • Security Posture: Running at lower levels means missing modern security features

Security Recommendation​

Aim to maintain your forest at the highest functional level supported by all domain controllers:

  1. Verify Compatibility: Ensure all DCs in all domains support the target level
  2. Test Applications: Verify critical applications work at the higher level
  3. Plan Maintenance Window: Schedule the upgrade appropriately
  4. Document Changes: Record the upgrade for audit and compliance purposes

How the Test Works​

This test retrieves the current forest functional level from Active Directory along with basic forest information including the root domain and domain count.

  • Test-MtAdDomainFunctionalLevel - Retrieves the domain functional level
  • Test-MtAdForestDomainCount - Counts domains in the forest

Test Metadata​

FieldValue
Test IDAD-FOR-01
SeverityMedium
SuiteActive Directory
CategoryAD.Forest
PowerShell testTest-MtAdForestFunctionalLevel
TagsAD, AD-FOR-01, AD.Forest

Source​

  • Pester test: tests/ad/domain/Test-MtAdForestFunctionalLevel.Tests.ps1
  • PowerShell source: powershell/public/ad/domain/Test-MtAdForestFunctionalLevel.ps1