Hi all!

I have a AD domain based on Samba 4.7.6.I created a group policy that
installs CA certificate as trusted root CA.

The policy works when security filtering is set to Authenticated Users. But
when I remove Apply permission of Authenticated Users in Delegation tab
(Read permission remains) and add Domain Computers to Security Filtering,
policy is not applied anymore.

I am a newbe in AD but I thought, that Read and Apply permissions for
Domain Computers should be enough if the policy changes computer
configuration only. Is that assumption wrong? Or should I look futher for a
problem in my Samba configuration?

I don't get any errors on my workstation when running gpupdate /force, the
policy is just not applied.

Any help would be appreciated!

