[Samba] GPO on a DC

David Mulder dmulder at samba.org
Tue Jun 21 16:05:58 UTC 2022

On 6/21/22 9:23 AM, samba-ml-en via samba wrote:
> userAccountControl=532480 is the value (SERVER_TRUST_ACCOUNT|TRUSTED_FOR_DELEGATION)
> As of oddjob-gpupdate I prefer to use winbind if possible, it is more complex but has better flexibility than SSSD.

oddjob-gpupdate isn't just for SSSD. You can use it in combination with 
Winbind also. In fact, you have to use oddjob-gpupdate in order to 
utilize user policies (at least for the moment, I will add this to 
winbind at some point).

*David Mulder*
Labs Software Engineer, Samba
1221 Valley Grove Way
Pleasant Grove, UT 84062

dmulder at suse.com

More information about the samba mailing list