Also I just found this about the July 2006 Samba release. It indicates that ACL selection from Windows client should now work.

===============================
Release Notes for Samba 3.0.23a
Jul 21, 2006
===============================
Common bugs fixed in 3.0.23a include:
o Failure to strip the domain name from groups when 'winbind
use default domain = yes'
o Failure in pam_winbind to correctly parse arguments.
o Bad token creation of local users on member servers not
running winbindd.
o Failure to add users or groups to ACLs using the Windows
object picker.
o Failure in file serving code when 'kernel oplocks = yes'.