Windows domains, part 4: the feature arc — Server 2008 R2 to 2019
Part 4from the Windows domains series · 6 parts in all
Between 2009 and 2019 the forest quietly acquired almost every operational safety net it now depends on. Each release added one or two big things; knowing which release introduced what is half of AD troubleshooting folklore.
2008/2008 R2: survivability
The Read-Only Domain Controller shipped in 2008 — a DC whose database you cannot write to and whose credential caching is administratively filtered, designed for branch offices and DMZs where a stolen DC is a real scenario. 2008 R2 added the Active Directory Recycle Bin (restore a deleted user with every group and attribute intact, no authoritative-restore surgery) and the Managed Service Account, the prototype of the feature that would end the "service account with a password that never expires" spreadsheet.
2012: virtualization and managed passwords
VM-Generation ID let DCs detect virtual-machine rollback — snapshot restores, the classic way to fork a domain's replication history — and self-heal instead of corrupting quietly. Group Managed Service Accounts (gMSA) made the domain rotate a service account's password automatically, with specific hosts allowed to retrieve it: passwords that no human ever knows.
2012 R2/2016: the hardening years
ADFS matured into the enterprise federation workhorse (SAML/OAuth for Office 365 before password-hash sync was even advisable). 2016 added Privileged Access Management — time-limited membership in administrative groups via MIM, the ancestor of today's PIM — plus LDAP signing enforcement options and continued hardening of NTLM's negotiation surface.
# 2008 R2: enable the Recycle Bin once per forest, restore with full fidelity
Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet `
-Target 'maplecart.local'
Get-ADObject -Filter 'displayName -eq "beth"' -IncludeDeletedObjects |
Restore-ADObject
# 2012: group Managed Service Accounts - passwords that rotate themselves
New-ADServiceAccount fleetAgent -DNSHostName fleetAgent.maplecart.local `
-PrincipalsAllowedToRetrieveManagedPassword "FLEET-SRV01$","FLEET-SRV02$"
Install-ADServiceAccount fleetAgent
# replication health from the 2012-era toolkit onward
Get-ADReplicationFailure -Target maplecart.local -Scope Forest
What 2019 conspicuously did
Windows Server 2019 shipped no new AD features at all — the message being that the schema and topology were done, and Microsoft's identity energy had moved to the cloud. That judgment call is the hinge of this whole series: the forest's last big on-prem feature generation happened just as hybrid identity became the real story. Part 5 picks up there — Entra Connect, the Primary Refresh Token, and the seam between the two worlds.