How to clean up orphaned SID's in ACEs in AD?
Posted
by
geoffc
on Server Fault
See other posts from Server Fault
or by geoffc
Published on 2010-11-04T12:50:22Z
Indexed on
2011/01/12
19:55 UTC
Read the original article
Hit count: 180
active-directory
|tombstones
As a follow up to my question Do backlinks clear in AD for deleted users I have another related but different question.
Since I am informed in the answers there that a deleted object's SID (Group or User, so assigning rights to group only minimizes the issue, and does not fix it) will remain within ACEs they have been assigned, leaving them orphaned.
Lotus Domino, which has similar issues with back references, has an adminp process to clean up such orphaned references.
Is there a similar process in AD that would allow you to clean up such orphaned SIDs floating around your domain?
© Server Fault or respective owner