The Active Directory Domain Controller
In Ubuntu Linux, the Samba suite is used to provide file and print services that are compatible with Windows networks (SMB/CIFS). While most users install the basic smbd and nmbd services to share a simple folder across a home network, the full Samba package also includes a highly advanced daemon: samba-ad-dc.service. This service is specifically designed to allow your Ubuntu machine to act as a fully functional Microsoft Active Directory Domain Controller, managing user authentications, group policies, and DNS for an entire fleet of Windows machines.
However, running an Active Directory Domain Controller is an incredibly specific and complex enterprise task. If you are simply trying to share a media folder with your smart TV, or if you are running a standard web server, this daemon is completely useless. Having it installed or attempting to start in the background wastes system memory, opens potential security vectors, and clutters your boot logs with errors as it fails to find the required Kerberos and DNS configurations. To secure your basic file server, you should disable this enterprise feature.
How to Disable the Samba-ad-dc Service
Because you likely still need the basic Samba file sharing services (smbd), you should not purge the entire package. Instead, you must explicitly mask the Active Directory service.
Warning: Only do this if you are using Samba for basic file sharing. Do not do this if you are actually running a Linux-based Active Directory environment.
- Open your Ubuntu Terminal or connect via SSH.
- First, stop the AD DC service if it happens to be running:
sudo systemctl stop samba-ad-dc.service
- Disable the service so it does not attempt to launch during the boot sequence:
sudo systemctl disable samba-ad-dc.service
- Because Samba’s internal tooling can sometimes attempt to call the AD DC components if misconfigured, you must firmly mask the service to prevent it from ever starting under any circumstances:
sudo systemctl mask samba-ad-dc.service
Your Ubuntu server is now restricted to standard file sharing and will no longer attempt to initialize enterprise Active Directory components.