Removing an old user from Active Directory?

  • Thread starter Thread starter George Hester
  • Start date Start date
G

George Hester

Is there anything special that needs to be done when removing a user from
Active Directory Users and Computers? Remove seems too simple. I am sure
there will be "junk" lying about. Thanks. Oh Windows 2000 SP 4 Advanced
Server.
 
George said:
Is there anything special that needs to be done when removing a user from
Active Directory Users and Computers? Remove seems too simple. I am sure
there will be "junk" lying about. Thanks. Oh Windows 2000 SP 4 Advanced
Server.
That's all I ever do (at least on the DC......

You may need to look at mailboxes on Exchange, profiles on TS servers
and any roaming profiles left on the server...

--

Regards,
Hank Arnold
Microsoft MVP
Windows Server - Directory Services
 
OK Hank. I removed in Security places where the user was so that they would
not be changed to S etc. stuff. But I just wanted to make sure there wasn't
anything else I should do.
 
George said:
OK Hank. I removed in Security places where the user was so that they would
not be changed to S etc. stuff. But I just wanted to make sure there wasn't
anything else I should do.

Could you expand on the statement "I removed in Security places where
the user was so that they would not be changed to S etc. stuff."? It's
not clear to me at all what you are doing...

--

Regards,
Hank Arnold
Microsoft MVP
Windows Server - Directory Services
 
George,

There are several other things to consider based on your environment. You
may have an Exchange mailbox left over. You may have a home directory or
user profile left on a file server somewhere. Did they store any files on
your file server that you might want to archive and get rid of?
To find out you can scan through the file servers looking for files where
that user is an owner. I recommend you do this before you remove the user.

Have you granted permissions anywhere in a file system or within Active
Directory that would make this user a direct Trustee? For example, did you
give them direct permissions to a folder on a share somewhere instead of
adding them to a group and then giving the group permissions? If you've
granted that user some permissions, and you delete the user, then you can
create orphaned permissions assignments. I've seen networks that when you
look at the permissions on a folder in a file system you see dozens of
orphaned SIDS in the Access Control List. This is undesirable for more than
one reason.

If you don't know where those permissions assignments may be then you might
need a tool to search for all files and folders controlled by the user. If
you've already deleted the user then you might want a tool that will search
your file system for orphaned SID assignments and clean them up.

There are scripts and tools available to help with this, DSRAZOR for Windows
is one of them. If you want to find out how DSRAZOR can help you locate and
fix these problems then you can take a look at
www.visualclick.com/?source=FSperms011508
 
Back
Top