<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Server 2008 R2: Active Directory Functional Levels</title>
	<atom:link href="http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 17 May 2012 08:33:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-16898</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Tue, 02 Nov 2010 14:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-16898</guid>
		<description>&lt;p&gt;You might want to add that this command should be run on the Domain Naming Master. (Mine was also the Schema Master so try that if the DNM trick does not work.)&lt;/p&gt;

&lt;p&gt;or else you may receive
Enable-ADOptionalFeature : A referral was returned from the server
At line:1 char:25&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You might want to add that this command should be run on the Domain Naming Master. (Mine was also the Schema Master so try that if the DNM trick does not work.)</p>

<p>or else you may receive
Enable-ADOptionalFeature : A referral was returned from the server
At line:1 char:25</p>]]></content:encoded>
	</item>
	<item>
		<title>By: jack</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-2113</link>
		<dc:creator>jack</dc:creator>
		<pubDate>Mon, 09 Nov 2009 05:26:57 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-2113</guid>
		<description>&lt;p&gt;There is no more such BDC term used by Windows 2003 and above.&lt;/p&gt;

&lt;p&gt;However, to increase functional leevl should not impact your current infrastructure, but to provide more features.&lt;/p&gt;

&lt;p&gt;Refer to the following KB,
http://technet.microsoft.com/en-us/library/cc771132(WS.10,printer).aspx&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>There is no more such BDC term used by Windows 2003 and above.</p>

<p>However, to increase functional leevl should not impact your current infrastructure, but to provide more features.</p>

<p>Refer to the following KB,
<a href="http://technet.microsoft.com/en-us/library/cc771132(WS.10,printer).aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/cc771132(WS.10,printer).aspx</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Craig</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1681</link>
		<dc:creator>Jonathan Craig</dc:creator>
		<pubDate>Wed, 28 Oct 2009 21:58:08 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1681</guid>
		<description>&lt;p&gt;Hi Simon,&lt;/p&gt;

&lt;p&gt;Thanks for sharing your insightful thoughts and suggestions - very helpful, and appreciated indeed.&lt;/p&gt;

&lt;p&gt;On a related note, we needed a quick and efficient way to enumerate nested security groups for security audits in AD R2 (i.e. find out which groups were nested in other groups.) So we asked our on-site MS consultant and he recommended using the Gold Finger from Paramount Defenses Inc.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Gold Finger&lt;/b&gt; pleasantly surprised us because not only was it endorsed by Microsoft but also 100% FREE and loaded with almost 250 useful Active Directory security, Exchange and ACL management reports. BTW, you can download it for free from &lt;a href=&quot;http://goldfinger.paramountdefenses.com&quot; rel=&quot;nofollow&quot;&gt;http://goldfinger.paramountdefenses.com&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thought I&#039;d share this with you incase it could help you too, especially if you&#039;re into AD security reporting.&lt;/p&gt;

&lt;p&gt;Thanks again, and looking forward to your next post.&lt;/p&gt;

&lt;p&gt;Best wishes,
Jonathan&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi Simon,</p>

<p>Thanks for sharing your insightful thoughts and suggestions &#8211; very helpful, and appreciated indeed.</p>

<p>On a related note, we needed a quick and efficient way to enumerate nested security groups for security audits in AD R2 (i.e. find out which groups were nested in other groups.) So we asked our on-site MS consultant and he recommended using the Gold Finger from Paramount Defenses Inc.</p>

<p><b>Gold Finger</b> pleasantly surprised us because not only was it endorsed by Microsoft but also 100% FREE and loaded with almost 250 useful Active Directory security, Exchange and ACL management reports. BTW, you can download it for free from <a href="http://goldfinger.paramountdefenses.com" rel="nofollow">http://goldfinger.paramountdefenses.com</a></p>

<p>Thought I&#8217;d share this with you incase it could help you too, especially if you&#8217;re into AD security reporting.</p>

<p>Thanks again, and looking forward to your next post.</p>

<p>Best wishes,
Jonathan</p>]]></content:encoded>
	</item>
	<item>
		<title>By: End of the World</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1655</link>
		<dc:creator>End of the World</dc:creator>
		<pubDate>Wed, 28 Oct 2009 10:11:08 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1655</guid>
		<description>&lt;p&gt;Thank&#039;s for sharing this
This is really interesting&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thank&#8217;s for sharing this
This is really interesting</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Price</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1563</link>
		<dc:creator>Simon Price</dc:creator>
		<pubDate>Mon, 26 Oct 2009 17:56:02 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1563</guid>
		<description>&lt;p&gt;Going to R2 2008 functional level will maintain all features of a 2003 level domain/forest and add the new 2008 R2 features. This said, your existing environment (Exchange 2003) should not be affected. Keep in mind this change is not reversible. So if you have a test environment, use it prior to making production changes, and in production make a backup on a DC before executing the change.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Going to R2 2008 functional level will maintain all features of a 2003 level domain/forest and add the new 2008 R2 features. This said, your existing environment (Exchange 2003) should not be affected. Keep in mind this change is not reversible. So if you have a test environment, use it prior to making production changes, and in production make a backup on a DC before executing the change.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: al all</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1506</link>
		<dc:creator>al all</dc:creator>
		<pubDate>Sun, 25 Oct 2009 16:18:39 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1506</guid>
		<description>&lt;p&gt;Question: in our environment we have PDC 2088 R2 &amp; BDC 2008 R2, both are operating on default level (Server 2003), and two Exchange 2003 Servers. Can I raise the PDC &amp; BDC to Server 2008 R2 Domain and Forest Functional Levels, without losing connection or effecting the regular functionality of the tow Exchange 2003 Servers? any extra info or precaution should I put in mind.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Question: in our environment we have PDC 2088 R2 &amp; BDC 2008 R2, both are operating on default level (Server 2003), and two Exchange 2003 Servers. Can I raise the PDC &amp; BDC to Server 2008 R2 Domain and Forest Functional Levels, without losing connection or effecting the regular functionality of the tow Exchange 2003 Servers? any extra info or precaution should I put in mind.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1458</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Tue, 20 Oct 2009 02:53:30 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1458</guid>
		<description>&lt;p&gt;Sure, that&#039;s fine.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Sure, that&#8217;s fine.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Polprav</title>
		<link>http://praetorianprefect.com/archives/2009/10/server-2008-r2-active-directory-functional-levels/comment-page-1/#comment-1427</link>
		<dc:creator>Polprav</dc:creator>
		<pubDate>Fri, 16 Oct 2009 13:29:48 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=758#comment-1427</guid>
		<description>&lt;p&gt;Hello from Russia!
Can I quote a post in your blog with the link to you?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hello from Russia!
Can I quote a post in your blog with the link to you?</p>]]></content:encoded>
	</item>
</channel>
</rss>

