Paul Williams [MVP]
2007-01-12 10:48:31 UTC
There's two reasons why you'll see a SID and not an object's CN.
The account no longer exists, i.e. it has been deleted.
The SID cannot be resolved, e.g. Power Users on a Domain Controller.
You are correct that there's no cleanup task. It's not the ADs job to
cleanup references to objects it holds, and the clients generally don't
clean up such things are there's valid reasons why a SID can't be resolved
(see above or temporary network problem).
The account no longer exists, i.e. it has been deleted.
The SID cannot be resolved, e.g. Power Users on a Domain Controller.
You are correct that there's no cleanup task. It's not the ADs job to
cleanup references to objects it holds, and the clients generally don't
clean up such things are there's valid reasons why a SID can't be resolved
(see above or temporary network problem).
--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net