It would seem that whilst a group such as Domain Admins is mapped to 'ID_TYPE_BOTH' in idmap.ldb, the OS will only accept the group as a user by number, not by name. i.e. 'chown Domain\ Admins:Domain\ Admins file.txt' will fail, but 'chown 3000013:Domain\ Admins file.txt' will succeed. Note that '3000013' is the GID for Domain Admins: getent group Domain\ Admins SAMDOM\domain admins:x:3000013:SAMDOM\administrator,SAMDOM\rowland
(In reply to Rowland Penny from comment #0) Closing this, it now appears to work on 4.15.7