It's not needed on Samba domain controllers.  Since Unix can't nest
groups, it would be tricky anyway.

It *is* needed on domain members, but only NT ones, because it is how
the user rights get granted to the domain users, etc.  Samba does not
have to do *anything* for it to work.  All it has to do is provide the
global groups, which it does.

To see what I mean, log onto an NT workstation and open User Manager.
Examine the local groups that are granted the right "Log on locally".
Examine the global groups that are members of those local groups.


