member server and check to see if you can change ACL's on a Share =20 You should find that with Kerberos enabled we are able to see objects in AD we were not previously able to display. =20 Also in the MMC Snap-In if you remove Everyone from the share you will no longer have access to the share. If you add everyone back in, they will have access. =20 You can also add ACL's via Windows Explorer as before.=20 =20 As you can see, this is an important ability you miss out on if you only use net ads join to get your Kerberos ticket. I would hope that a samba team contributor eventually implements this into the net ads join function better so this isn't needed. =20 =20 -Give credit where it is due- Originally Submitted by:=20 Duncan Fiander =20 =20 =20 =20