How to clean up orphaned SID's in ACEs in AD?
- by geoffc
As a follow up to my question Do backlinks clear in AD for deleted users I have another related but different question.
Since I am informed in the answers there that a deleted object's SID (Group or User, so assigning rights to group only minimizes the issue, and does not fix it) will remain within ACEs they have been assigned, leaving them orphaned.
Lotus Domino, which has similar issues with back references, has an adminp process to clean up such orphaned references.
Is there a similar process in AD that would allow you to clean up such orphaned SIDs floating around your domain?