Bug 10360 - Raising forest/domain functional from Windows: Not sufficiant privileges
Raising forest/domain functional from Windows: Not sufficiant privileges
Status: NEW
Product: Samba 4.1 and newer
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB
4.1.3
x64 Linux
: P5 minor
: ---
Assigned To: Andrew Bartlett
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-01-07 11:14 UTC by Marc Muehlfeld
Modified: 2016-08-26 01:03 UTC (History)
1 user (show)

See Also:


Attachments
Screenshot of Message and Domain Admin Group Membership properties (447.47 KB, image/png)
2014-01-07 11:14 UTC, Marc Muehlfeld
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marc Muehlfeld 2014-01-07 11:14:17 UTC
Created attachment 9556 [details]
Screenshot of Message and Domain Admin Group Membership properties

When you try to raise the domain or forest functional level from Windows (tried on W7 64-Bit) with "AD Domains and Trusts", the dialogs say "Not sufficiant privileges to raise the forest functional level" respectively "domain functional level"


The MS Documentation (http://technet.microsoft.com/en-us/library/cc730985.aspx) says, the Account has to be member of the Enterprise Admins group, what the Domain Admin, I've used, is. See attached Screenshot.



With samba-tool it's no problem to raise the levels:
# samba-tool domain level raise --domain-level=2008
Domain function level changed!
All changes applied successfully!

# samba-tool domain level raise --forest-level=2008
Forest function level changed!
All changes applied successfully!
Comment 1 Marc Muehlfeld 2016-08-26 01:03:27 UTC
Update: Re-checked using a Samba 4.5.0rc2 DC: Problem still exists.