subinacl.exe / help / cleandeletedsidsfromは以下を提供します:
/ cleandeletedsidsfrom = domain [= dacl | sacl | owner | primarygroup | all]
delete all ACEs containing deleted (no valid) Sids from DomainName
You can specify which part of the security descriptor will be scanned
If the owner is deleted, new owner will be the Administrators group.
If the primary group is deleted, new primary group will be the Users group.
これを/ samobjectスイッチと共に使用して、ユーザーまたはグループに適用できるようです。