Can you double-check that your pam configuration for pam_winbind is configured to use required or requisite rather than sufficient?
It's possible that the required or requisite defaults aren't sufficient but may still be possible to configure using the more complicated pam syntax. Search for 'valueN' in /usr/share/doc/libpam-doc/txt/Linux- PAM_SAG.txt.gz for some details. I don't know off-hand if the pam_winbind module supports these finer-grained controls but it's possible it does. Thanks ** Information type changed from Private Security to Public Security ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1913851 Title: pam_winbind should reject disabled users To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1913851/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs