The value of the parameter (a string) is the Active Directory functional level that this Domain Controller will claim to support. Possible values are : 2008_R2: Similar to Windows 2008 R2 Functional Level 2012: Similar to Windows 2012 Functional Level 2012_R2: Similar to Windows 2012 R2 Functional Level 2016: Similar to Windows 2016 Functional Level Normally this option should not be set as Samba will operate per the released functionality of the Samba Active Directory Domain Controller. However to access incomplete features in domain functional level 2016 it may be useful to set this value, prior to upgrading the domain functional level. If this is set manually, the protection against mismatching features between domain controllers is reduced, so all domain controllers should be running the same version of Samba, to ensure that behaviour as seen by the client is the same no matter which DC is contacted. Setting this to 2016 will allow raising the domain functional level with samba-tool domain level raise --domain-level=2016 and provide access to Samba's Kerberos Claims and Dynamic Access Control feature. The Samba's Kerberos Claims and Dynamic Access Control features enabled with 2016 are incomplete in Samba 4.19. 2008_R2 2016