one can create a ou=users,dc=test,dc=lan or a ou=system,dc=test,dc=lan Organizational Unit on a Samba-AD DC.
It is however forbidden on a MS-AD (error message when trying with RSAT).
Moreover, having such an OU in the Samba-AD domain prevents joining a MS-AD domain controller (join fails).
So in order to be compliant with Microsoft behavior, Samba-AD should refuse to create those OU :
I guess the name attribute needs to be unique at each level
and cn=users ad cn=system already exist...
*** This bug has been marked as a duplicate of bug 14225 ***