{"id":4547,"date":"2017-04-26T22:03:13","date_gmt":"2017-04-26T20:03:13","guid":{"rendered":"http:\/\/michlstechblog.info\/blog\/?p=4547"},"modified":"2017-04-27T16:07:10","modified_gmt":"2017-04-27T14:07:10","slug":"windows-cleanup-permissions-from-deleted-active-directory-objects","status":"publish","type":"post","link":"https:\/\/michlstechblog.info\/blog\/windows-cleanup-permissions-from-deleted-active-directory-objects\/","title":{"rendered":"Windows: Cleanup Permissions from deleted Active Directory Objects"},"content":{"rendered":"<div class=\"twoclick_social_bookmarks_post_4547 social_share_privacy clearfix 1.6.4 locale-en_US sprite-en_US\"><\/div><div class=\"twoclick-js\"><script type=\"text\/javascript\">\/* <![CDATA[ *\/\njQuery(document).ready(function($){if($('.twoclick_social_bookmarks_post_4547')){$('.twoclick_social_bookmarks_post_4547').socialSharePrivacy({\"services\":{\"flattr\":{\"uid\":\"Michl\",\"status\":\"on\",\"the_title\":\"Windows%3A%20Cleanup%20Permissions%20from%20deleted%20Active%20Directory%20Objects\",\"the_excerpt\":\"Hi%2C%0D%0A%0D%0Ain%20domain%20environments%20it%20sometimes%20happens%20that%20user%20or%20groups%20would%20be%20deleted%20but%20is%20still%20authorized%20on%20many%20object%2C%20i.e.%20filesystems%2C%20shares%20etc..%0D%0A%0D%0A%20%28more%26hellip%3B%29\",\"txt_info\":\"2 clicks for more data protection:\\r\\n\\r\\nOnly when you click here, the button will be come active and you can send your recommendation to Flattr. When activating, data are transmitted to third parties. \",\"perma_option\":\"off\"}},\"txt_help\":\"When you activate these fields by clicking, information to Flattr may be transferred abroad, and probably may also stored there.\",\"settings_perma\":\"Enable permanently and accept data transmission. \",\"info_link\":\"http:\\\/\\\/www.heise.de\\\/ct\\\/artikel\\\/2-Klicks-fuer-mehr-Datenschutz-1333879.html\",\"uri\":\"https:\\\/\\\/michlstechblog.info\\\/blog\\\/windows-cleanup-permissions-from-deleted-active-directory-objects\\\/\",\"post_id\":4547,\"post_title_referrer_track\":\"Windows%3A+Cleanup+Permissions+from+deleted+Active+Directory+Objects\",\"display_infobox\":\"on\"});}});\n\/* ]]> *\/<\/script><\/div><p>Hi,<\/p>\n<p>in domain environments it sometimes happens that user or groups would be deleted but is still authorized on many object, i.e. filesystems, shares etc..<\/p>\n<p><!--more--><br \/>\nicacls just shows the SID of the orphaned object but cannot delete such a permission<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nC:\\&gt; icacls E:\\Folder\r\nE:\\Folder\r\n....\r\n          S-1-5-21-12820228123-987170752-682003330-877999:(OI)(CI)(M)\r\n          S-1-5-21-12820228123-987170752-623643330-876799:(OI)(CI)(M)\r\n....\r\n<\/pre>\n<p>But there is a good old resource kit tool which can do this. Microsofts <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=23510&#038;751be11f-ede8-5a0c-058c-2ee190a24fa6=True\" target=\"_blank\">subinacl<\/a><\/p>\n<p>There are two possibilities to do a cleanup with subinacl. Delete all entries from deleted user or groups or delete a specific SID(s). <\/p>\n<p>This example deletes 2 specific SIDs from the folder E:\\Folder and all subdirectories <\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nC:\\&gt; subinacl.exe \/subdirectories E:\\Folder \/revoke=S-1-5-21-12820228123-987170752-682003330-877999 \/revoke=S-1-5-21-12820228123-987170752-623643330-876799\r\n<\/pre>\n<p>and this all orphaned SID permissions, but you have to specify the DomainName to which the SIDs belongs to.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nC:\\&gt; subinacl.exe \/subdirectories E:\\Folder \/cleandeletedsidsfrom=DomainName=all\r\n<\/pre>\n<p>Michael<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi, in domain environments it sometimes happens that user or groups would be deleted but is still authorized on many object, i.e. filesystems, shares etc..<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[1010,1009,1008,1011,265,358,264,1012,20],"class_list":["post-4547","post","type-post","status-publish","format-standard","hentry","category-windowsknowhow","tag-cleanup","tag-deleted-groups","tag-deleted-user","tag-filesystem","tag-icacls","tag-permissions","tag-sid","tag-subinacl","tag-windows-2"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/posts\/4547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/comments?post=4547"}],"version-history":[{"count":3,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/posts\/4547\/revisions"}],"predecessor-version":[{"id":4550,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/posts\/4547\/revisions\/4550"}],"wp:attachment":[{"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/media?parent=4547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/categories?post=4547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michlstechblog.info\/blog\/wp-json\/wp\/v2\/tags?post=4547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}