(I'm trying here as well, the SLES9 list isn't very active) I'm getting frustrated.. I've set up Samba to use LDAP, but I can't get group mapping to work whatever I try. I'd like to map some LDAP groups to MS groups, like the "Domain Users" and "Domain Admins" groups, but it just doesn't work. First I tried to add the LDAP group, then in the screen for "Additional Group Settings" I opened "Edit remaining attributes of LDAP group" and tried to modify the field "sambasid" from ending in 1001 to end with -512 (Domain Admins). I saved it all, and opened up the group editor again, the sambasid field was back to -1001. What am I doing wrong here? I can't find any leads in the SLES9 docs either.. My smb.conf contains this: [global] workgroup = TEST-DOM map to guest = Bad User passdb backend = smbpasswd ldapsam:ldap://localhost, username map = /etc/samba/smbusers printcap cache time = 750 printcap name = cups add machine script = /usr/sbin/useradd -c Machine -d /var/lib/nobody -s /bin/false %m$ logon script = users.bat logon path = \\%L\profiles\.msprofile logon drive = I: logon home = \\%L\%U\.9xprofile domain logons = yes os level = 65 preferred master = Yes domain master = Yes wins support = yes ldap admin dn = cn=Administrator,dc=the-server,dc=net ldap group suffix = ou=group ldap idmap suffix = ou=Idmap ldap machine suffix = ou=Computers ldap suffix = dc=the-server,dc=net ldap ssl = no ldap user suffix = ou=people idmap backend = ldapsam:ldap://localhost printer admin = @ntadmin, root, administrator cups options = raw store dos attributes = Yes include = /etc/samba/dhcp.conf local master = yes encrypt passwords = yes