Вот вам вывод моего testparm. Мб не идеальный, но работает.
[global]
workgroup = *имя домена, например, CORP*
realm = *полное имя домена, например, CORP.COMPANY.COM*
server string = %h server (Samba, Ubuntu)
server role = member server
security = ADS
auth methods = winbind
log file = /var/log/samba/log.%m
max log size = 1000
dns proxy = No
usershare allow guests = Yes
panic action = /usr/share/samba/panic-action %d
template shell = /bin/bash
winbind separator = /
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = Yes
winbind offline logon = Yes
idmap config * : range = 10000-20000
idmap config * : backend = tdb
map acl inherit = Yes
store dos attributes = Yes
vfs objects = acl_xattr
[IT]
comment = IT
path = /srv/smb/it
read only = No