AD-FOR-01 - Forest functional level should be retrievable
Overviewβ
The forest functional level determines which Active Directory features are available across all domains in the forest. Higher functional levels unlock important forest-wide security capabilities:
- Windows Server 2016+: Enables features like privileged access management (PAM) across the forest
- Windows Server 2012 R2+: Provides access to forest-wide authentication policies and silos
- Global Features: Some features require forest-wide consistency to function
- Security Posture: Running at lower levels means missing modern security features
Security Recommendationβ
Aim to maintain your forest at the highest functional level supported by all domain controllers:
- Verify Compatibility: Ensure all DCs in all domains support the target level
- Test Applications: Verify critical applications work at the higher level
- Plan Maintenance Window: Schedule the upgrade appropriately
- Document Changes: Record the upgrade for audit and compliance purposes
How the Test Worksβ
This test retrieves the current forest functional level from Active Directory along with basic forest information including the root domain and domain count.
Related Testsβ
Test-MtAdDomainFunctionalLevel- Retrieves the domain functional levelTest-MtAdForestDomainCount- Counts domains in the forest
Related linksβ
- Microsoft Learn: Active Directory Domain Services functional levels
- ANSSI Active Directory checkpoints: Insufficient forest and domains functional levels
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-FOR-01 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdForestFunctionalLevel |
| Tags | AD, AD-FOR-01, AD.Forest |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdForestFunctionalLevel.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdForestFunctionalLevel.ps1


