It took me a while to understand how SID's and RID's worked. The recent discussion "SIDs and UIDs and RIDS - Oh My!" helped quite a bit. Here are two Microsoft documents that I have found to be useful. http://support.microsoft.com/default.aspx?scid=kb;en-us;243330 http://support.microsoft.com/default.aspx?scid=kb;en-us;297951 The entries placed by the smbldap tool into the LDAP directory make a lot more sense to me now.