Its littered throughout the docs eg.. https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs At best its *poor practice* which should not be frowned upon, but it just shows a real disconnect with real world users and systems, where admins are not "Domain Admins".