>>>>> "Eric" == Eric J Feldhusen <efeldhusen.lists at gmail.com> writes:

    Eric> I've had similar problems before, make sure you don't have
    Eric> any unix group mapped to multiple Windows groups.

Thanks for the suggestion.

It turns out that the problem was my fault (of course!).

Previously I had seen a SID with no mapping in the Administrators
group on the client computer. So I deleted it!

Turns out this was the SID for the "Domain Admins" group, but it
didn't show up as such because the mapping on the domain server was
wrong at the time. So I added Domain Admins again, using the correct
SID and it works now.

PS. I never saw your post to the mailing list (I only got the copy you
sent directly to me), despite it being addressed to
samba at lists.samba.org - strange.
