๐Ÿง Active Directory on Linux (Samba)

A beginner-friendly guide to running an Active Directory-compatible domain controller on a Linux server with Samba

1. What is Samba's AD mode?

Samba is an open-source implementation of the SMB protocol. Since Samba 4, it can run a full Active Directory domain controller (DC) on Linux. That means Windows and Linux machines join the domain just like they join a Microsoft Windows Server DC โ€” same single sign-on, same groups, same unified logins โ€” but using only open-source software on commodity Linux hardware.

๐ŸŽ›๏ธ Analogy โ€” A Lookalike Front Desk
Microsoft's Active Directory is a famous front desk that hands out badges. Samba is a lookalike front desk on Linux: it speaks the same language (the AD protocols), issues the same kind of badges, and every employee in the building doesn't care which front desk handles registration โ€” a Windows PC can't tell the difference.

๐ŸŽฏ Why choose it instead of a Windows DC?

ReasonDetail
CostNo Windows Server licenses โ€” ideal for labs, homelabs, and small orgs
Run it anywhereA Raspberry Pi or a small VM is enough for small deployments
TransparentConfig is text files and YAML; the whole service is inspectable
Long-standing protocolSamba has been speaking SMB and AD protocols for decades

2. Benefits of a Linux AD DC

๐Ÿ”‘ Windows clients work
Windows PCs join and authenticate to a Samba DC just like a Microsoft one.
๐Ÿง Linux friendly
Kerberos + LDAP/SSSD make Linux machines first-class domain citizens too.
๐Ÿ’ฐ No license cost
Ideal for test labs, internal networks, and homelabs.
๐Ÿ“ One config store
Everything (users, groups, computers) lives in Samba's LDAP database.
๐Ÿ”„ AD compat
Uses the same Kerberos/LDAP standards Microsoft AD uses.
๐Ÿงผ Lightweight
Runs on modest hardware โ€” one DC for dozens of users is trivial.

3. Samba DC vs Windows Server AD

Windows Server ADSamba on Linux (AD DC)
Microsoft product, Windows-only OSOpen-source, runs on Linux
Full GUI tooling built in (ADUC, GPMC)Mostly CLI (samba-tool commands)
Every GPO feature supportedCommon GPOs work; edge features may differ
Requires license per DCFree to run as many DCs as you like
Commercial supportCommunity support (and paid options via vendors)
๐Ÿš— Analogy โ€” Official Dealer vs Expert Mechanic
Windows AD is the official dealer: full service, full warranty, but every task happens the OEM way and costs. Samba is the expert independent mechanic: identical engine, speaks the same protocols, configurable and cost-effective โ€” but you're the one with the manuals.

4. What's bundled under the hood

๐Ÿ”ง The pieces of a Samba AD DC

PieceRole
Kerberos (krb5)Distributes tickets for authentication โ€” the service that proves you are who you say you are
LDAPThe directory database holding users, groups, and objects
DNSSamba can serve the AD DNS records the domain needs
SMB/file sharesThe classic file sharing piece (SMB/CIFS)
samba-toolThe Swiss-Army CLI to manage every piece of the domain

5. Step-by-Step: Provision a Domain

The following uses a real example โ€” a domain called corp.example.com with NetBIOS name CORP. Run on a fresh Debian/Ubuntu server as root.

Install the required packages
$ sudo apt update
$ sudo apt install -y samba
$ samba --version    # should be 4.x

On Debian/Ubuntu, the samba package already includes samba-tool. Put a hostname, static IP address, and a proper DNS forwarder โ€” AD is very DNS-sensitive.

Set the machine name and time
$ sudo hostnamectl set-hostname dc01
    # ensure /etc/hosts maps hostname โ†’ static IP

AD (Kerberos) is very picky about clocks โ€” you must use NTP (e.g. chronyd) so your DC's clock is in sync.

Back up the default config and provision
$ sudo mv /etc/samba/smb.conf /etc/samba/smb.conf.orig
  $ sudo samba-tool domain provision \
      --use-rfc2307 \
      --domain=CORP \
      --realm=corp.example.com \
      --adminpass='S3cure_Admin>Pass123' \
      # creates a new smb.conf and the AD database

--use-rfc2307 adds POSIX attributes so Linux systems can map accounts to UID/GID. Keep the admin password long and strong โ€” it becomes the AD Administrator account.

Enable and start Samba as a DC
$ sudo systemctl disable --now winbind smbd nmbd
  $ sudo systemctl enable --now samba-ad-dc
  $ systemctl status samba-ad-dc  # should be running

A Samba DC runs as samba-ad-dc, not the usual smbd/nmbd pair. On Debian the service is samba-ad-dc; on some distros it's samba.

Verify the domain
$ sudo samba-tool domain level show
  $ sudo samba-tool domain info 127.0.0.1
  $ kinit [email protected]   # tests Kerberos
๐Ÿ› ๏ธ Analogy โ€” Registering with the Front Desk
Provisioning writes the master guest book (the LDAP database), picks a badge-issuing method (Kerberos), and declares who's in charge (the Administrator). From then on, every machine and person that joins the domain checks in against the exact same handy book.

6. Managing users and groups

Everything behind the DC is done with samba-tool. It's the Linux equivalent of AD Users and Computers.

# Create a user
$ sudo samba-tool user create jane.doe    # prompts for password

# Reset a user's password
$ sudo samba-tool user setpassword jane.doe

# Disable an account (e.g. when someone leaves)
$ sudo samba-tool user disable jane.doe
# Manage groups
  $ sudo samba-tool group create sales
  $ sudo samba-tool group addmembers sales "jane.doe","john.smith"
  $ sudo samba-tool group listmembers sales

  # List all users and groups
  $ sudo samba-tool user list
  $ sudo samba-tool group list

๐Ÿ” Audit & management commands

CommandWhat it does
samba-tool user listList all users
samba-tool group listList all groups
samba-tool group addmembers <g> <u>Add users to a group
samba-tool group listmembers <g>Show members of a group
samba-tool dns query ...Inspect/change DNS records
samba-tool dbcheck --yesConsistency-check the AD database
samba-tool domain backup offlineCreate a backup of the domain

7. Joining clients to the domain

๐ŸชŸ Windows client

Point the PC's DNS at the Linux DC, then the standard flow: Settings โ†’ System โ†’ About โ†’ Rename this PC (advanced) โ†’ Member of โ†’ Domain, typing corp.example.com and an eligible account (e.g. Administrator). Reboot โ€” you'll log in with a domain account.

๐Ÿง Linux client (via realm/sssd)

$ sudo apt install -y realmd sssd adcli krb5-user
  $ sudo realm join corp.example.com
  $ getent passwd jane.doe    # now resolves the AD user
  $ su - jane.doe            # logs in with AD credentials

8. Quick Reference

CommandWhat it does
samba-tool domain provisionCreate a new domain (run once on first setup)
samba-tool user createAdd a user
samba-tool groupCreate/manage groups
kinitTest Kerberos login
realm joinJoin a Linux client to AD
smbclientTest/query SMB shares
samba-tool dbcheckVerify database integrity

9. Best Practices

๐Ÿ•› Keep the clock synced
Kerberos fails when clocks drift. Use NTP/chrony on every DC.
๐Ÿ“ž DNS is law
Point every member at the DC's DNS first; DNS breaks = domain breaks.
๐Ÿ“ฆ Automate user creation
Write a small samba-tool script and use it for every new hire.
๐Ÿ—ž๏ธ Back up the AD database
samba-tool domain backup offline is your vital safety net.
๐Ÿงฏ Start with a dry-run
Keep a throwaway VM to practise realm join before a real migration.
๐Ÿงญ When in doubt
samba-tool dbcheck --help and the Samba Wiki are your friends.

Samba turns a plain Linux box into a full AD domain controller โ€” identity, auth and policy for every machine.
One provisioning command and a few config lines, and your network has a home.

Created by jcmatira