Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 8565

Error 8565: raise the forest functional level before adding this controller

11 min read Updated October 5, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

Error 8565 is ERROR_DS_FOREST_VERSION_TOO_LOW: the operating system on the server you are promoting no longer supports the forest functional level you have, so it will not join. Nothing is wrong with the server, the media or your credentials. The forest level has to come up first, and it cannot while any domain controller in scope is below it.

Run these on an existing domain controller, in an elevated PowerShell session

Get-ADForest | Format-List Name,ForestMode
Get-ADDomain | Format-List Name,DomainMode
Get-ADDomainController -Filter * | Format-Table Name,OperatingSystem,OperatingSystemVersion,Site -AutoSize
repadmin /replsummary
  1. Read the two levels and the controller list together. Any server running an operating system older than the level you need is the blocker, whether or not it is switched on.
  2. Fix replication before anything else. Raising a level on top of a replication fault leaves controllers disagreeing about the level itself, which is a worse problem than the one you started with.
  3. Deal with each blocking controller: upgrade it, or remove it with Uninstall-ADDSDomainController run on that machine. A server that no longer exists still counts until its metadata is cleaned up.
  4. Raise the domain first and then the forest, as a member of Enterprise Admins, from Active Directory Domains and Trusts or with Set-ADDomainMode and Set-ADForestMode. The forest level can never exceed the lowest domain level.

Microsoft states that changes to domain and forest functional levels are irreversible, and that undoing one means a forest recovery to an earlier point in time. Take a system state backup of two healthy controllers before you raise anything.

If the promotion prerequisite now passes, you are done. If it does not, the next section explains which half of the check is failing and what else pins a level down.

Why it happens

A functional level is a contract. It states the behaviours every domain controller holding a copy of the partition is guaranteed to support, which is why Active Directory refuses to run at a level any member controller cannot honour. The constraint you have hit is the same rule read from the other end: each server release declares the oldest forest and domain it is willing to join, and refuses to become a domain controller in anything older.

Microsoft’s wording for 8565 is that the version of the operating system installed on this server no longer supports the current forest functional level, and that you must raise the forest functional level before this server can become a domain controller. 8566 says the same thing about the domain. Neither is a bug, a permissions problem or a media problem, which is why running the wizard again produces the same answer every time.

Two more codes sit in the same group and mean the opposite. 8563 is ERROR_DS_FOREST_VERSION_TOO_HIGH and 8564 is ERROR_DS_DOMAIN_VERSION_TOO_HIGH: the level is higher than the server you are installing supports, and you must upgrade the operating system instead. That direction has no configuration fix at all, because functional levels do not come down.

The floor is not new, and it is worth being precise about because a lot of advice implies each release raises it. Microsoft states that Windows Server 2019 or later requires a Windows Server 2008 forest functional level as a minimum, and groups current releases with that. If you are hitting 8565, your forest is at a level older than that – which usually means it has been running, untouched, since well before anyone currently on the team arrived.

One surviving down-level domain controller

You have this one if The controller list shows a server on an older operating system than everything else, very often in a branch site nobody signs into.

  1. Find out what else it does first: which operations master roles it holds, whether it is a global catalog, and whether its site uses it for DNS.
  2. Move every one of those functions to a controller you are keeping, and correct any DHCP option or static setting naming its address as a DNS server.
  3. Demote it with Uninstall-ADDSDomainController run on that server.
  4. Let the removal replicate, confirm with a replication summary, then raise the domain and the forest.

Demote gracefully wherever you can. Powering the server off and cleaning its metadata by hand works, but it leaves you doing recovery work you did not have to do.

A domain controller that exists only in the directory

You have this one if The list names a server that no longer physically exists, and replication has been failing against a name nobody recognises.

  1. Confirm the machine is genuinely gone and will not be returned to the network. This step is not reversible.
  2. In Active Directory Users and Computers, with Advanced Features on, delete its computer object from the Domain Controllers organisational unit and confirm the permanently-offline prompt.
  3. Remove any surviving NTDS Settings object and server object in Active Directory Sites and Services.
  4. Clear its records from DNS, then retry the raise.

If the deletion itself is refused with error 8340, work through the metadata cleanup process properly before coming back to the level raise.

The forest is held down by a domain you are not in

You have this one if The domain you are promoting into is already at the level you need, and the forest still reports an older mode.

  1. Enumerate every domain in the forest and read each one’s mode, rather than checking only the one in front of you.
  2. Raise each domain that is behind, dealing with its own down-level controllers first.
  3. Only then raise the forest. Its level can never exceed the lowest domain level in it.

The schema was never prepared for the new build

You have this one if The levels look right and the promotion still fails during preparation, or preparation reports that it cannot complete.

  1. For a new server being promoted, you do not normally run adprep at all – Microsoft states the tools are integrated into the PowerShell and Server Manager experiences.
  2. For an in-place upgrade of an existing domain controller, you must run adprep /forestprep and adprep /domainprep manually.
  3. Run forestprep as a member of Schema Admins, Enterprise Admins and Domain Admins; domainprep needs Domain Admins.
  4. Run forestprep once per forest for each newer version of Windows Server, and domainprep once in each domain that will host upgraded controllers.

Full reference

Which half of the check is refusing you

Code Name What it means
8565 ERROR_DS_FOREST_VERSION_TOO_LOW This operating system no longer supports the current forest functional level. Raise the forest level
8566 ERROR_DS_DOMAIN_VERSION_TOO_LOW The same at domain level. Raise the domain level
8563 ERROR_DS_FOREST_VERSION_TOO_HIGH The forest level is higher than this operating system supports. Upgrade the operating system
8564 ERROR_DS_DOMAIN_VERSION_TOO_HIGH The same at domain level. Upgrade the operating system

So the two pairs point in opposite directions, and mixing them up wastes a change window. Too low means the directory is older than the server; too high means the server is older than the directory. Only the first has a configuration answer.

What the raise actually requires

  • Every domain controller in the domain must already be running at least the version of Windows Server you are raising the domain level to.
  • You must be a member of Enterprise Admins, or equivalent, to raise the forest level.
  • The forest level cannot exceed the lowest domain level in the forest.
  • Replication must be converged first, so that every controller sees the same set of controllers before the level is written.
  • The change is irreversible. Microsoft’s guidance is explicit: to undo it you must perform a forest recovery to revert to an earlier point in time.

Take a system state backup of two healthy domain controllers before raising a level, and confirm the backups are readable. There is no supported way back afterwards short of a forest recovery, which is a project rather than an afternoon.

Commands worth knowing here

Command What it does
Get-ADForest Reads the forest, including its current ForestMode
Get-ADDomain Reads the domain, including its current DomainMode
Get-ADDomainController -Filter * Lists every controller with the operating system it runs, including ones that are switched off
Set-ADForestMode -Identity <forest> -ForestMode <mode> Raises the forest level. Windows2025Forest is an accepted value
Set-ADDomainMode -Identity <domain> -DomainMode <mode> Raises the domain level
Uninstall-ADDSDomainController Removes AD DS from the server you run it on
repadmin /replsummary Summarises replication health across the estate

Doing it through the console instead

  1. Open Active Directory Domains and Trusts.
  2. In the console tree, right-click the domain node and select Raise Domain Functional Level. Repeat for every domain that is behind.
  3. Right-click Active Directory Domains and Trusts itself and select Raise Forest Functional Level.
  4. Let the change replicate, then read the level back from a controller in a different site before you touch the promotion again.

When the level is right and promotion still fails

  • Check that the removal of the old controller has actually replicated everywhere, not just to the server you are standing at.
  • Check DNS for records still advertising the removed controller, particularly under the _msdcs zone, which will keep clients and tools trying to reach it.
  • Confirm no read-only controller in a forgotten site is still below the level. They are easy to miss because nobody administers them directly.
  • Confirm you are promoting into the domain you think you are, in a forest with more than one domain.
  • Run the promotion prerequisite check on the new server before committing, so a second failure costs you a minute rather than a maintenance window.

When a licence is the actual fix

Where the servers holding your level down cannot be upgraded, the licence genuinely is the fix: there is no configuration path from an out-of-support domain controller to a forest a current server will join, and no registry value that lowers the minimum. Arco supplies Windows Server 2025 Standard. Check one thing before ordering, because it changes the answer surprisingly often: a Standard licence carries the right to run two virtual machines plus one Hyper-V host, so a virtual replacement controller may already be covered by a host you have licensed. And if your blocker turns out to be stale metadata rather than a live server, cleanup costs nothing and you need nothing from us.

Every code this article covers

Code What it points at Source
8565 ERROR_DS_FOREST_VERSION_TOO_LOW, 0x2175: this operating system no longer supports the current forest functional level, which must be raised first Microsoft Learn
8566 ERROR_DS_DOMAIN_VERSION_TOO_LOW, 0x2176: the same comparison failing at domain level Microsoft Learn
8563 ERROR_DS_FOREST_VERSION_TOO_HIGH, 0x2173: the operating system version is incompatible with the current forest functional level and must be upgraded Microsoft Learn
8564 ERROR_DS_DOMAIN_VERSION_TOO_HIGH, 0x2174: the same, measured against the domain functional level Microsoft Learn

Confirm the fix worked

  1. Get-ADForest and Get-ADDomain read back the new levels from two controllers in different sites.
  2. Get-ADDomainController -Filter * no longer lists any server you removed.
  3. The promotion prerequisite check on the new server passes without the level error.
  4. After promotion, replication summarises clean across the estate and the new controller appears in the site you intended.
  5. A system state backup taken after the raise restores successfully in a test, since there is no way back from the level change itself.

Questions people ask about this

Can I raise the forest level without touching the old domain controller?

No. The check reads the directory, and the old controller is in it. While its NTDS Settings object exists it counts, switched on or not.

Will raising the level break anything for my users?

Functional levels constrain domain controllers, not member servers or workstations, so clients authenticate exactly as before. What can break is software or an appliance bound to a controller you removed on the way, so check what points at the old server first.

Do I always have to buy licences to fix 8565?

No. If the blocker is stale metadata, cleanup costs nothing. If it is a virtual machine on a host with spare licensed capacity, no purchase is involved either. You only buy when you need a licensed instance you do not already hold.

Can I promote first and raise the level afterwards?

No. The comparison runs before the server is written into the directory, so there is no partially promoted state to tidy up later.

Can I put the level back if something breaks?

No. Microsoft states the change is irreversible and that undoing it requires a forest recovery to an earlier point in time. That is why the backup comes before the raise, not after it.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error FRS Event ID 13508: SYSVOL still on File Replication Service and unsupported License Error Error 8568: the functional level will not rise while legacy DCs remain Free Fix LDAP 533 and 532: binds refused because of the account state in AD Free Fix Event ID 1311 KCC errors: site links that cannot build a working topology
โ† Back to Knowledge Base