(Last Update: July 7)
On July 8, Microsoft will release an important security update for Active Directory Domain Controllers for Windows Server versions prior to 2025.
This update modifies the Microsoft RPC Netlogon protocol to improve security by tightening access checks for a set of RPC requests. Samba running as domain members in these environments will be impacted by this change if a specific configuration is used. See below for details on the affected configurations.
Windows Server version 2025 is already equipped with these specific security hardenings. Microsoft plans to deploy them to all supported Windows Server versions down to Windows Server 2008.
Who is affected?
Samba installations that act as member servers in Windows AD domains will be affected if they are configured to use the 'ad' idmapping backend. Samba servers that do not use this configuration will not be affected by the change – at least according to our current knowledge and understanding – and no further action is required.
However, current versions of Samba with the affected configuration will no longer function correctly once the Microsoft update has been applied. Users will not be able to connect to the SMB service provided by Samba for any domain that uses the ‘ad’ idmapping backend.
What is SerNet doing?
The SAMBA+ team at SerNet, along with other members of the international Samba team, has been collaborating with Microsoft. Changes to Samba are currently being developed and tested to ensure full compatibility between Samba and Microsoft products. The Samba team aims to release updated packages on Monday evening (UTC+2).
Updated SAMBA+ packages, which will restore full compatibility, are planned to be made available before Microsoft's rollout.
What you should do:
- Check your configuration if you’re running Samba in a Windows AD environment.
- Watch out for new SAMBA+ package updates early next week (starting July 7th) .
- Apply the update before Microsoft’s rolls out the patch.
All SAMBA+ updates are included in active subscriptions.
If you do not yet have a subscription, visit the SAMBA+ shop (EUR) or SAMBA+ shop (USD) for access.
For any questions or individual support, feel free to contact us directly – our team is here to help.