A beginner-friendly guide to running an Active Directory-compatible domain controller on a Linux server with Samba
Samba is an open-source implementation of the SMB protocol. Since Samba 4, it can run a full Active Directory domain controller (DC) on Linux. That means Windows and Linux machines join the domain just like they join a Microsoft Windows Server DC โ same single sign-on, same groups, same unified logins โ but using only open-source software on commodity Linux hardware.
| Reason | Detail |
|---|---|
| Cost | No Windows Server licenses โ ideal for labs, homelabs, and small orgs |
| Run it anywhere | A Raspberry Pi or a small VM is enough for small deployments |
| Transparent | Config is text files and YAML; the whole service is inspectable |
| Long-standing protocol | Samba has been speaking SMB and AD protocols for decades |
| Windows Server AD | Samba on Linux (AD DC) |
|---|---|
| Microsoft product, Windows-only OS | Open-source, runs on Linux |
| Full GUI tooling built in (ADUC, GPMC) | Mostly CLI (samba-tool commands) |
| Every GPO feature supported | Common GPOs work; edge features may differ |
| Requires license per DC | Free to run as many DCs as you like |
| Commercial support | Community support (and paid options via vendors) |
| Piece | Role |
|---|---|
| Kerberos (krb5) | Distributes tickets for authentication โ the service that proves you are who you say you are |
| LDAP | The directory database holding users, groups, and objects |
| DNS | Samba can serve the AD DNS records the domain needs |
| SMB/file shares | The classic file sharing piece (SMB/CIFS) |
samba-tool | The Swiss-Army CLI to manage every piece of the domain |
The following uses a real example โ a domain called corp.example.com with NetBIOS name CORP.
Run on a fresh Debian/Ubuntu server as root.
$ sudo apt update $ sudo apt install -y samba $ samba --version # should be 4.x
On Debian/Ubuntu, the samba package already includes samba-tool. Put a hostname, static IP address, and a proper DNS forwarder โ AD is very DNS-sensitive.
$ sudo hostnamectl set-hostname dc01 # ensure /etc/hosts maps hostname โ static IP
AD (Kerberos) is very picky about clocks โ you must use NTP (e.g. chronyd) so your DC's clock is in sync.
$ sudo mv /etc/samba/smb.conf /etc/samba/smb.conf.orig $ sudo samba-tool domain provision \ --use-rfc2307 \ --domain=CORP \ --realm=corp.example.com \ --adminpass='S3cure_Admin>Pass123' \ # creates a new smb.conf and the AD database
--use-rfc2307 adds POSIX attributes so Linux systems can map accounts to UID/GID. Keep the admin password long and strong โ it becomes the AD Administrator account.
$ sudo systemctl disable --now winbind smbd nmbd $ sudo systemctl enable --now samba-ad-dc $ systemctl status samba-ad-dc # should be running
A Samba DC runs as samba-ad-dc, not the usual smbd/nmbd pair. On Debian the service is samba-ad-dc; on some distros it's samba.
$ sudo samba-tool domain level show $ sudo samba-tool domain info 127.0.0.1 $ kinit [email protected] # tests Kerberos
Everything behind the DC is done with samba-tool. It's the Linux equivalent of AD Users and Computers.
# Create a user $ sudo samba-tool user create jane.doe # prompts for password # Reset a user's password $ sudo samba-tool user setpassword jane.doe # Disable an account (e.g. when someone leaves) $ sudo samba-tool user disable jane.doe
# Manage groups $ sudo samba-tool group create sales $ sudo samba-tool group addmembers sales "jane.doe","john.smith" $ sudo samba-tool group listmembers sales # List all users and groups $ sudo samba-tool user list $ sudo samba-tool group list
| Command | What it does |
|---|---|
samba-tool user list | List all users |
samba-tool group list | List all groups |
samba-tool group addmembers <g> <u> | Add users to a group |
samba-tool group listmembers <g> | Show members of a group |
samba-tool dns query ... | Inspect/change DNS records |
samba-tool dbcheck --yes | Consistency-check the AD database |
samba-tool domain backup offline | Create a backup of the domain |
Point the PC's DNS at the Linux DC, then the standard flow: Settings โ System โ About โ Rename this PC (advanced) โ Member of โ Domain, typing corp.example.com and an eligible account (e.g. Administrator). Reboot โ you'll log in with a domain account.
$ sudo apt install -y realmd sssd adcli krb5-user $ sudo realm join corp.example.com $ getent passwd jane.doe # now resolves the AD user $ su - jane.doe # logs in with AD credentials
| Command | What it does |
|---|---|
samba-tool domain provision | Create a new domain (run once on first setup) |
samba-tool user create | Add a user |
samba-tool group | Create/manage groups |
kinit | Test Kerberos login |
realm join | Join a Linux client to AD |
smbclient | Test/query SMB shares |
samba-tool dbcheck | Verify database integrity |
samba-tool script and use it for every new hire.
samba-tool domain backup offline is your vital safety net.
realm join before a real migration.
samba-tool dbcheck --help and the Samba Wiki are your friends.
Samba turns a plain Linux box into a full AD domain controller โ identity, auth and policy for every machine.
One provisioning command and a few config lines, and your network has a home.
Created by jcmatira