Re: SID security folder permissions for deleted AD user



Thanks for the suggestions.
Barry

"Joe Richards [MVP]" wrote:

> You already have the advice you need, I just want to point out one thing.
>
> The names aren't replaced with SIDs. The permission lists (called ACLs) have
> SIDs listed in them, not usernames. When you display the ACLs in most tools,
> they resolve the SIDs to names for you. If they can't be resolved, then SIDs are
> shown.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> Barry Hallman wrote:
> > My network necessarily has many users that are assigned explicit security
> > rights on several folders. When one of these users is deleted in AD, I have
> > checked the security settings on the folders and find that the user name has
> > been replaced by an SID with the same permissions. Do these SIDS for the
> > deleted users get purged from the system automatically? If so, what triggers
> > this event? If not automatically, is there an easy way to perform this
> > function? Thanks in advance
>
.



Relevant Pages

  • Re: SID security folder permissions for deleted AD user
    ... The SIDs will not be purged automatically. ... folder permissions on servers to look for matches against existing AD ... > rights on several folders. ... > deleted users get purged from the system automatically? ...
    (microsoft.public.windows.server.active_directory)
  • Re: SID security folder permissions for deleted AD user
    ... The permission lists have SIDs listed in them, ... When you display the ACLs in most tools, they resolve the SIDs to names for you. ... Do these SIDS for the deleted users get purged from the system automatically? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Migrating NT to Win 2000 AD single domain
    ... Created folders on E: partition on NT server for NT users and groups. ... Migrated users and groups (including SIDs) from NT domain to AD domain. ...
    (microsoft.public.win2000.active_directory)
  • Re: Resolving Sid to User Name when Examining DACL
    ... "Mr. Lee" wrote in message ... > I'm checking to make sure certain people have permissions on certain folders> on my server. ... > When I right click the folder /properties /Security, I get the standard list> of SIDS that normally resolve to a name quickly. ...
    (microsoft.public.win2000.security)
  • Re: SID security folder permissions for deleted AD user
    ... >My network necessarily has many users that are assigned explicit security ... >rights on several folders. ... How can I remove invalid domain SIDs from the my file system permissions? ...
    (microsoft.public.windows.server.active_directory)