Jump to content

Recommended Posts

Posted (edited)

Hi

 

Ive just gone into the properties of the DNS server, clicked on the security tab and found a couple of unknown accounts. Is it fine just to remove these entries and the group for our decommissioned exchange server?

 

DNS2.JPG

 

Thanks

Edited by techie08
Posted
Should be fine to delete them. They are accounts for old user who have been deleted from AD. Most likely old technicians or network manager accounts. Also, no harm in just leaving them...
  • Thanks 1
Posted

Before removing them - set them to deny, see if anything breaks. If it does you know those accounts are required and what for. If you happy leaving them there in deny mode, should you ever need you can re allow them.

 

IIRC usually this happens when an account is removed from AD or the local SAM, but the Access Control List (ACL) still retains the security ID (token) for that account.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...