Re: SID security folder permissions for deleted AD user



You already have the advice you need, I just want to point out one thing.

The names aren't replaced with SIDs. The permission lists (called ACLs) have SIDs listed in them, not usernames. When you display the ACLs in most tools, they resolve the SIDs to names for you. If they can't be resolved, then SIDs are shown.

   joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


Barry Hallman wrote:
My network necessarily has many users that are assigned explicit security rights on several folders. When one of these users is deleted in AD, I have checked the security settings on the folders and find that the user name has been replaced by an SID with the same permissions. Do these SIDS for the deleted users get purged from the system automatically? If so, what triggers this event? If not automatically, is there an easy way to perform this function? Thanks in advance
.



Relevant Pages

  • Re: Win2K Migration
    ... So that old ACLs point to the NEW ... >> I'm confused as to what needs to be replicated when migrating from ... >> Is this due to the SIDs not having been migrated? ... > Not from server to server. ...
    (microsoft.public.windows.server.migration)
  • Re: write access denied on directories after rebuild
    ... yes, sir, i know the sids are from the previous installs. ... the acls are untouchable with either Windows Explorer ... this means this rebuild has made all my partitions other than my system ... >> they sometimes have permissions for Everyone, ...
    (microsoft.public.win2000.setup)
  • Re: Moving ACLs to new server
    ... to move data and retain ACLs --> robocoby ... I want to retain the ACLs but the problem is that we're using local ... SIDS are refering to the old server name. ...
    (microsoft.public.windows.server.security)
  • Re: migrating file permissions
    ... > the filer won't change if you just move him and don't change the ACLs. ... > earlier by just adding the newdomain SIDs to the ACLs where the olddomain ... But the SidWalk Migration Suite is the one I'd ... it's documented in the support tools help. ...
    (microsoft.public.windows.server.active_directory)
  • Re: write access denied on directories after rebuild
    ... You need to take ownership of the files this will rewrite ths SIDS giving ... i can not get write access to the acls to change the ... > permission with respect to the logged-on user, ... > this means this rebuild has made all my partitions other than my system ...
    (microsoft.public.win2000.setup)

Loading