Bug 10360 - Raising forest/domain functional from Windows: Not sufficiant privileges
Summary: Raising forest/domain functional from Windows: Not sufficiant privileges
Status: NEW
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB (show other bugs)
Version: 4.1.3
Hardware: x64 Linux
: P5 minor (vote)
Target Milestone: ---
Assignee: Andrew Bartlett
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-07 11:14 UTC by Marc Muehlfeld
Modified: 2023-02-24 06:04 UTC (History)
2 users (show)

See Also:


Attachments
Screenshot of Message and Domain Admin Group Membership properties (447.47 KB, image/png)
2014-01-07 11:14 UTC, Marc Muehlfeld
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marc Muehlfeld 2014-01-07 11:14:17 UTC
Created attachment 9556 [details]
Screenshot of Message and Domain Admin Group Membership properties

When you try to raise the domain or forest functional level from Windows (tried on W7 64-Bit) with "AD Domains and Trusts", the dialogs say "Not sufficiant privileges to raise the forest functional level" respectively "domain functional level"


The MS Documentation (http://technet.microsoft.com/en-us/library/cc730985.aspx) says, the Account has to be member of the Enterprise Admins group, what the Domain Admin, I've used, is. See attached Screenshot.



With samba-tool it's no problem to raise the levels:
# samba-tool domain level raise --domain-level=2008
Domain function level changed!
All changes applied successfully!

# samba-tool domain level raise --forest-level=2008
Forest function level changed!
All changes applied successfully!
Comment 1 Marc Muehlfeld 2016-08-26 01:03:27 UTC
Update: Re-checked using a Samba 4.5.0rc2 DC: Problem still exists.
Comment 2 Marc Muehlfeld 2017-02-26 14:13:31 UTC
Problem still exists in 4.6.0rc3.