Hi Jerry, thanks a lot for your replay , but ... I think its my mistake , my problem description wasnt the best i fear, so let me try again; situation is as following : AD users can connect to a given share without any problem , the users are pure (AD)NT-USERS , without any unix-pendant . Now the problem; I am not able to restrict connections to a given AD group , getent group $group|grep $usr shows me the user is in the requested AD group, but valid users = "domain\group" fails in every combination Additionally i have to make clear , that this groups only exist in AD , not on unix host , maybe thats the problem I also tried to "expand" the valid users directive like valid users = `getent groups $groupname` think i have overlooked an important point..., but may be theres a workaround thanks in advance for your efforts kind regards martin schreiber Siemens Business Services CCN-ITS Betrieb Wien GUD Gudrunstrasse 11 A-1101 Wien Martin Schreiber Phone +43 5 1707 47565 Server-Administration Fax +43 5 1707 57560 mailto:martin.a.schreiber@siemens.com http://www.sbs.at