[Samba] SaMBa functional level

Pisch Tamás pischta at gmail.com
Wed Mar 27 11:18:33 UTC 2024


>
> Others have integrated Azure AD with Samba without the FL increase, and
> the key step would be the adprep work,

Then I will do it without increasing the FL. What do I have to do with
adprep?

> but regardless the main risk
> with using the FL 2012 or FL2016 'early' in Samba 4.19 or 4.20 is that
> we don't have any further protection against 'mixed domains' if you use
> the silos, claims or authentication policy features.  So if you have some
> DCs on 4.19 and some on a later version with the full support, eg 4.21 or
> partial support (4.20), then you will have inconsistent behaivour between
> your DCs.
>
I will use only 4.19 DCs.


More information about the samba mailing list