I use ever samba-tool (however in samba 4.7 doesn't implement the "fine grain" features that offer the 4.9 version), but I know some people using GPOs.
Using GPOs solve your problem if your clients are Windows machines, but these policies will not apply to GNU/Linux flavors.
Further, this way, you will not need to care about the sysvol replicatión through rsync (if you have some more domain controllers). XD
Cheers!