Is there a way to change the lookup string (correct me if I am wrong here) regarding the schema attribute Samba uses for AD authentication? Not if this is accurate but it seems the AD lookup queries the CN attribute within an active directory user account. My problem is I have legacy user accounts which under the CN attribute have not just their login name but their last name as well: ex. CN=John Doe,OU=Users,DC=domain,DC=com Is there a way to specify the schema attribute Samba will use for AD authentication such as the 'principalName' attribute? Thanks. -- Jas