New Security Features in Samba 4.22 Support Windows Server 2016 Functional Level
Microsoft’s Windows Server 2016 Functional Level, introduced with enhanced security functions, is now fully supported in Samba 4.22, enhancing security within Samba domains.
Since the release of Samba version 4.19, it has been possible to set up Microsoft’s Windows Server 2016 Functional Level on Linux Domain Controllers. This functional level introduces additional security mechanisms such as the FAST protocol and enables the use of Authentication Policies and Authentication Silos.
Both features are designed to improve authentication security. However, it was only with the spring release of version 4.22 that the Samba team fully implemented these capabilities, allowing their use in a Samba domain.
The FAST protocol (Flexible Authentication Secure Tunneling), also known as Kerberos Armoring, extends the Kerberos protocol by enhancing the security of the Kerberos authentication process and the querying of service tickets. Without FAST, messages exchanged during the Kerberos authentication process and the service ticket request process are transmitted in plaintext.
These advancements reflect a significant step forward in the open-source community’s efforts to ensure compatibility and security in mixed-server environments, highlighting the commitment to robust security standards.


