[Samba] Expected behaviour of domain\administrator on Linux AD domain member

Rowland penny rpenny at samba.org
Tue Apr 21 08:35:15 UTC 2020

On 20/04/2020 22:50, Rob Tho via samba wrote:
> Dear all,
> I have set a small test domain in virtualbox.
> 1. Samba AD DC on Debian bullseye testing 4.11.6
> 2. Samba domain member Debian Stretch 4.10.14
> 3. Windows 10 Enterprise evaluation version 1909
> Window ACL:
> Share Permissions
> Domain Admins (SAMBA\Domain Admins) -- Full Control
> Domain Admins (SAMBA\Domain Users) -- Change
No, that is wrong, put it back to 'Everyone', Allow 'Full Control, 
Change, Read'
> Security
Does it help if I tell you that a better name for the 'Security' tab 
would be 'NTFS permissions'
> Is this the expected behaviour of the domain\administrator acccount?
No, it works for myself
> I would preferably want to do all domain admin from the
> domain\administrator account logged into a windows 10 machine if that is
> possible.

Yes it is, just as long as you follow the wiki, I have now updated the 



> Many thanks for your help,
> RT

More information about the samba mailing list