Re: SID security folder permissions for deleted AD user



The SIDs will not be purged automatically. This is why it is generally
preferable to use groups, rather than assign permissions directly to user
objects, as groups do not change as often.

It shouldn't be too difficult to put together a script that cycles through
folder permissions on servers to look for matches against existing AD
objects and then report any objects that don't match.

Tony
www.activedir.org

"Barry Hallman" <BarryHallman@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AFEF7964-58BA-43B8-BFED-E86F140A08D1@xxxxxxxxxxxxxxxx
> My network necessarily has many users that are assigned explicit security
> rights on several folders. When one of these users is deleted in AD, I
> have
> checked the security settings on the folders and find that the user name
> has
> been replaced by an SID with the same permissions. Do these SIDS for the
> deleted users get purged from the system automatically? If so, what
> triggers
> this event? If not automatically, is there an easy way to perform this
> function? Thanks in advance


.



Relevant Pages

  • RE: Migrate ACLs to new server
    ... If we copy the folder from one member server to another, ... all permissions assigned to the domain user or groups. ... they will have different SIDs. ... To preserve NTFS permissions when migrating folders, please use NTBackup, ...
    (microsoft.public.windows.server.migration)
  • Re: SID security folder permissions for deleted AD user
    ... > The names aren't replaced with SIDs. ... The permission lists have ... >> rights on several folders. ... >> deleted users get purged from the system automatically? ...
    (microsoft.public.windows.server.active_directory)
  • Re: NTFS Security Question.
    ... A subordinate object DOES not inherit the PARENT perms (in ... will assume "Nebulous" permissions that refer to the LINK ... The trick is to PROPOGATE to all FILES (not Folders and Files - that would ... Since Windows 2000 deny NTFS permission does not work ...
    (microsoft.public.windowsxp.security_admin)
  • RE: ISA 2004 REPORT FAILURE
    ... Did as you suggested and turned auditing on for the system and folders ... that is setting the wrong permissions of the folders ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 REPORT FAILURE
    ... the ISA Reports still fail because ... I can change the permissions manually ... on the ISALogs and ISASummaries folders ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)