The group members of the "Domain Admins" group don't seem to have the same rights as the user "Administrator".
Created attachment 4424 [details]
Logfile of SAMBA
I discovered this when I added a new user, assigned it to the "Domain Admins" group and tried to add his user account to the "Cert Publishers" group (only for testing) with him as logged in user.
And I think I've also just found the cause: Only "builtin administrators" are seen as administrators (consider security_token.c:159 "security_session_user_level").
I forgot that we had this bug in #6199.
*** This bug has been marked as a duplicate of bug 6199 ***