[Samba] Setting Win ACLs via Comp Managment, connection to Member Server warning

I try to follow the instructions

A big screen pops up with when an attempt is made to connect to member
server, then connection is granted but I am suspitious if changes can
be made.

SeDiskOperatorPrivilege on ADDC is granted to BUILTIN\Administrators
and Domain Admins

But the Member Server has that permission granted only to
Is this normal? Should the permissions be set on the member server
instead, not on the ADDC? or whould they propagate across from ADDC to
Member Server...?

thank for hints

best regards

