How to clean up orphaned SID's in ACEs in AD?

Posted by geoffc on Server Fault See other posts from Server Fault or by geoffc
Published on 2010-11-04T12:50:22Z Indexed on 2011/01/12 19:55 UTC
Read the original article Hit count: 161

As a follow up to my question Do backlinks clear in AD for deleted users I have another related but different question.

Since I am informed in the answers there that a deleted object's SID (Group or User, so assigning rights to group only minimizes the issue, and does not fix it) will remain within ACEs they have been assigned, leaving them orphaned.

Lotus Domino, which has similar issues with back references, has an adminp process to clean up such orphaned references.

Is there a similar process in AD that would allow you to clean up such orphaned SIDs floating around your domain?

© Server Fault or respective owner

Related posts about active-directory

Related posts about tombstones