so the question was a bit premature... But I do have another.
Why do I have SIDs listed on the Security Tab for objects in Active
Directory? One I'm looking at is for a user object; it has no permissions.
For another user object, one SID has no permissions, another has Read
permissions...
...and...
I am wondering how to get rid of the sid/object of a deleted user account as I believe it’s screwing up some exchange 2000 tasks. For instance, userA has delegated rights to it's mailbox to userB; userB leaves the company and her account is deleted but the object’s delegated access to the mailbox remains; when one tries to schedule a meeting for userA, they correctly receive replies that userB is no longer valid but it's a nuisance for the user to receive these emails.
I can not remove userB’s access however, as windows tells me that it’s from inherited permissions and that in order to remove it I would need to remove inherited permissions all they way to the top of the domain – not easy task. The ‘user’ is simply a SID