and to remove those orphaned SIDs you could use SUBINACL (make sure you 
download the lastest version from the MS site)
 
Met vriendelijke groeten / Kind regards,
Ing. Jorge de Almeida Pinto
Senior Infrastructure Consultant
MVP Windows Server - Directory Services
 
LogicaCMG Nederland B.V. (BU RTINC Eindhoven)
(   Tel     : +31-(0)40-29.57.777
(   Mobile : +31-(0)6-26.26.62.80
*   E-mail : <see sender address>

________________________________

From: [EMAIL PROTECTED] on behalf of Akomolafe, Deji
Sent: Thu 2007-01-04 10:53
To: [email protected]
Subject: RE: [ActiveDir] SID Deleted users remains in NTS permission.


It's "normal". You should be permissioning your resources with groups instead 
of directly with user accounts. Groups tend to last longer, so you don't have 
to deal with the horrible SIDs.
 

Sincerely, 
   _____                                
  (, /  |  /)               /)     /)   
    /---| (/_  ______   ___// _   //  _ 
 ) /    |_/(__(_) // (_(_)(/_(_(_/(__(/_
(_/                             /)      
                               (/       
Microsoft MVP - Directory Services
www.akomolafe.com - we know IT
-5.75, -3.23
Do you now realize that Today is the Tomorrow you were worried about Yesterday? 
-anon

________________________________

From: Yann
Sent: Thu 1/4/2007 1:52 AM
To: [email protected]
Subject: [ActiveDir] SID Deleted users remains in NTS permission.


Hello all & Happy new year ! :)
 
AD 2k3 sp1 in FFL mode.
 
When i delete a user or group from AD, and these objects have permissions on 
ntfs permissions, i usually see their sids remaining in those file & directory 
ACLs.
 
Is this normal ? If not,what could be the reason(s) & how to investigate this 
issue ?
 
Thanks,
 
Yann
 
 

__________________________________________________
Do You Yahoo!?
En finir avec le spam? Yahoo! Mail vous offre la meilleure protection possible 
contre les messages non sollicités 
http://mail.yahoo.fr Yahoo! Mail 



This e-mail and any attachment is for authorised use by the intended 
recipient(s) only. It may contain proprietary material, confidential 
information and/or be subject to legal privilege. It should not be copied, 
disclosed to, retained or used by, any other party. If you are not an intended 
recipient then please promptly delete this e-mail and any attachment and all 
copies and inform the sender. Thank you.

<<winmail.dat>>

Reply via email to