http://samba.cdpa.nsysu.edu.tw/samba...html#id2518205
Not sure that's possible with Samba. It seems to be able to act as a NT4 PDC, but not AD. We're [unfortunately] using AD at work to do exactly that. Lock down 2k/XP PC's so the end users don't screw them up with screen savers/spyware/etc.
The only thing I've been trying to do is come up with a way to change their AD password via LDAP. (PHP interface) I have all the right bits, but it looks like I have to convince the windows admins to enable a few things.. bah.
-r