> Not sure what you are proposing is going to work, AD expects every user
> to be a member of Domain Users, even though there is nothing in AD to
> show membership. 


> Do you require this user to visible on all domain machines ?
> It might help if you could explain how you are going to use your new
> user 'mta'

No. Probably quoting a message of a month ago does not help...

I simply need to have a/some LDAP access to do LDAP queries; this 'mta'
examples, need to me to do email/aliases procesing in exim.

Practically, users in 'Restricted' group does not need to logon nor to
do anything on the domain, apart logging into the LDAP and do some
''generic'' queries.
I set to users in that group a random/complex password and forgot about
it, but i'm thinking of doing the 'right' things, lowering the account
privileges to the minimum.

Probably is a generic 'Active Directory' question, not a specific Samba
one, but... i've not found relevant info out there...


