[Samba] Winbind does not show all groups of all users

Dipl.-Ing. Péter Varkoly peter at varkoly.de
Mon Mar 16 14:21:09 UTC 2020

I'm using 4.10.13 as AD and have the issue that winbind does not show
correct the group membership of some users. # Global
parameters[global]      ldap server require strong auth =
no        netbios name = admin        realm =
XXXX.LOKAL        workgroup = XXXX        dns forwarder =        server role = active directory domain
controller        idmap_ldb:use rfc2307 = Yes        winbind enum users
= No        winbind enum groups = No        wide links =
Yes        unix extensions = No
        bind interfaces only = yes        interfaces =,        ntlm auth = yes        template shell = /bin/bash
        socket options = TCP_NODELAY TCP_KEEPIDLE=240 TCP_KEEPCNT=4
For examle the user sta is member of the group 10A:ldbsearch -H
/var/lib/samba/private/sam.ldb CN=10A | grep stainstanceType: 4member:
ldbsearch -H /var/lib/samba/private/sam.ldb CN=sta | grep 10AmemberOf:
But id does not show this:uid=4000821(XXXXX\sta) gid=100(users)
And:wbinfo --user-groups sta100400000540014573000009
What is wrong with this user??The most of the user have not this

Dipl.-Ing. Péter Varkoly
Greuleinweg 37.
D-90411 Nürnberg

