[Samba] Enabling recycle vfs in [global] on an AD DC disables creation of GPO's

Sebastian Arcus s.arcus at open-t.co.uk
Thu Apr 27 13:58:57 UTC 2017

As per my other post, enabling the recycle vfs module in the [global] 
section of smb.conf on a Samba AD DC kills the ability to create GPO's 
through RSAT with the error message:

"This security ID may not be assigned as the owner of this object"

It probably affects other things as well on the AD DC. I've searched 
through Samba.org and googled in general, and couldn't find any clear 
info as to if recycle vfs should or shouldn't be configured in [global]. 
For me it has certainly worked fine in [global] for years, with Samba as 

Could the information above be added in the wiki or documentation 
somewhere - to save others some head scratching, please.

More information about the samba mailing list