On Microsoft active directory, when a group has more than 1500 members, the member attribute is returned with "member;range=0-1499" add_remove_group_members check targetmember_dn in member attribut : https://github.com/samba-team/samba/blob/415f9f07456e3fd24063e7508d8b2553df020c21/python/samba/samdb.py#L445 this will not work with member;range=0-1499 attribut The problem is that this doesn't throw an error, it just won't work.
Interestingly enough, we fixed this for a previous iteration of our tools in https://bugzilla.samba.org/show_bug.cgi?id=707