I have quite a few Windows accounts with numeric user names. We sync with AD, so I'm guessing these are accounts that are now disabled in AD, and when syncing to LF they just get a numeric value.
So, I'm assuming it's ok to delete all of these?
I have quite a few Windows accounts with numeric user names. We sync with AD, so I'm guessing these are accounts that are now disabled in AD, and when syncing to LF they just get a numeric value.
So, I'm assuming it's ok to delete all of these?
There are other reasons you can get the "AD SID display issue" like Repository Server not having permissions to query all the necessary AD user object properties worth being aware of.
In this case though, the "Last Login" dates all being a ~year or more ago is strongly suggestive of disabled accounts, especially if the rest of the users are still displaying names as expected.
Yes, the rest of the user names are displaying as expected. If this is normal handling of disabled AD accounts, I'll can delete them manually, unless, of course, there's a setting somewhere that would delete them automatically?
There isn't an automatic cleanup of disabled users in the repository, to the best of my knowledge. Directory Server has some options for how to handle disabled and deleted users with its AD tombstone options, but the repository listing doesn't have any levers I'm aware of.