Okay, so I did this to myself. I overlooked an important sentence on the
"https://wiki.samba.org/index.php/Samba_%26_Windows_Profiles". The
sentence that instructs to do "Profile share using Windows ACLs"
***OR*** "Profile share with using POSIX ACLs".

So, I have reset the permissions to how they were before I messed them
up doing the "POSIX ACLs" part. Went back through the W7 client and
correctly set permissions (via Windows Explorer) as instructed on the

I still cannot write profiles to the /home/samba/NTDOM/profiles
directory. I think I am confused on the "Administrator" portion of the
wiki page. 

In the text box, the top line discusses the "Administrator" permission
settings. (Below "Administrator" lists "Domain Users" and "CREATOR
OWNER".) In the graphic that appears just above the text box, the
graphic illustrates setting permissions for the "\SAMDOMadmin . . ." so,
am I setting for my DCAdministrator or the member server administrator? 

And then begs the question, am I looking for 'getent group Domain Users'
on the DC or the member server? 


On 2015-03-05 11:49, Rowland Penny wrote: 

> On 05/03/15 17:22, Bob of Donelson Trophy wrote:
OK, the problem here is that Unix has to know who 'Domain Users' is
before it will/can change the group ownership of a directory.

I take it that the passwd & group lines in /etc/nsswitch.conf have had
'winbind' added to them and if you run 'pam-auth-update' it shows
winbind amongst the authentication methods.

Does Domain Users have a gidNumber ? If not then modify the 'Domain
Users' object in AD and add one.

You have to get 'getent group Domain Users' to return the group info
before you can go any further.


