On Thu, Mar 16, 2017 at 09:19:45AM +0100, Stefan Metzmacher wrote: > I don't understand the above statement, you want to implement > 'map untrusted to domain' on the AD DC itself? > I'm strongly against that, there's really no need for it. That's the current behaviour of the AD DC. People depend on it. Volker