[Samba] Windows Server 2019 Domain Controller Compatibility

ralph strebbing blackbirdralph at gmail.com
Fri Mar 11 14:14:17 UTC 2022

On Thu, Mar 10, 2022 at 4:29 PM Rowland Penny via samba
<samba at lists.samba.org> wrote:
> You could join it as a Domain member, would that work for the logs ?
Unfortunately no, because the info isn't being replicated to that
server from what I can tell.
So to your point Rowland, I'm not looking to necessarily increase the
functionality level if It'll let me, based on what Aaron has said, I
should be able to achieve this with 2019?

On Thu, Mar 10, 2022 at 5:12 PM Andrew Bartlett <abartlet at samba.org> wrote:

> That should work, provided you are willing to use the current Windows
> 2008R2 functional level.  Bugs in windows previously caused issues and
> were the reason we did a lot of work to implement 'adprep' (so we would
> be prepared for FL 2012R2 even if not operating it it), but it should
> work.
> We have great audit logs, we just don't provide them in the format
> windows does because those protocols are a pile of work (binary XML and
> XML queries for filtering, on top of DCE/RPC).
And unfortunately it's looking like I need the windows format for this
program. But confirming the above, I should be good to just join the
server to the existing forest on the lower domain functionality level?
If so, I'll give it a shot later, just wanted to make sure that I
wouldn't be breaking any replication stuff with the current samba
domain controllers by doing this.


More information about the samba mailing list