The Samba-Bugzilla – Bug 12618
Winbind on a DC doesn't show a 'ID_TYPE_BOTH' as a user by name.
Last modified: 2017-03-09 12:11:19 UTC
It would seem that whilst a group such as Domain Admins is mapped to 'ID_TYPE_BOTH' in idmap.ldb, the OS will only accept the group as a user by number, not by name.
i.e. 'chown Domain\ Admins:Domain\ Admins file.txt' will fail, but 'chown 3000013:Domain\ Admins file.txt' will succeed.
Note that '3000013' is the GID for Domain Admins:
getent group Domain\ Admins