[Samba] Windows ACLs on share

We are in the process of switching over shares from the old way of doing
this to Windows ACLs:

disable "valid users" "write list" etc

and set ACLs via Windows Explorer ...

And I struggle.

I am asking for a way to "start ACLs from scratch".

I ran "setfacl -b -R" on the dir on the samba server and did a "chown -R
root:10513" to hand it to "domain users"

in Windows Explorer we try to edit the Permissions in "Computer
Management" and get errors around writing to some "container" (I get the
msg in german, would have to google for english error msg)


Could someone pls advise?

Addon: a second share works fine with ACLs already, so samba itself
should be OK.

