Hi, finally everything is working fine on my Samba 4.6 AD Domain member server after _exactly_ following https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs (no more fiddling with acl_xattr:ignore system acls = yes, thanks Rowland Penny). Next thing i wanted to try is vfs_shadow_copy2 (with LVM snapshots: https://wiki.samba.org/index.php/Rotating_LVM_snapshots_for_shadow_copy). But as soon as i enable "vfs objects = shadow_copy2" for a share i can't administer file permissions ("Security") via Windows (as "Domain Admin") anymore. This happens even without any snapshots (it's the same when there are snapshots). Why? I tried disabling SELinux, no avail. I'm attaching some "log level = 9" logs and hope someone can enlighten me. Thanks Matthias