I am getting the same error. Configuring idmap to use AD does not seem be in 
used by idmap.

The ephermal ID you are getting in idmap show is probably a residue from before 
the AD is configured. Once you remove the /var/idmap/idmap.db and restart it, 
you would not receive these any more. 

When I am accessing the CIFS from a windows box, idmap is not able to get the 
info from the AD, even though it gets it when doing a get-namemap
This message posted from opensolaris.org
