I'm not AD expert, but the department requesting this service wants to ease the management of their windows environments. We currently use LDAP server from Oracle to managed our applications data. One of those applications is where all identity data is created. So it would be nice to just make AD use that active directory server and keep AD out of the mix. Instead of switching all applications to store data in the AD server. I didn't think Samba covered all AD functions. I might be wrong, I've only ever used Samba for print and file sharing. I'm open to ideas, but I'm not a big MS fan, and primary develop, not manage workstations. Thanks.