Hi, I've set up a Samba 4.1.6 AD controller and a Member Server according to the Wiki. All running quite well so far. However, I've a problem concerning file permissions. I've successfully granted the group 'MYDOM\Domain Admins' the SeDiskOperatorPrivilege. This doesn't seem to have an effect. For members of this group (and all other users in fact) it is only possible to change NT ACLs for files which they own. What is the SeDiskOperatorPrivilege supposed to do? I didn't set the 'enable privileges' parameter in smb.conf, as the man page states that this option is deprecated and set to 'yes' by default. However, when I run samba-tool testparm -v, it lists 'enable privileges = No'. Should this be explicitely enabled? Best regards Andreas