Documentation forAccess Rights Manager

Delete empty groups

Background / Value

Over time, empty groups accumulate in your Active Directory. These reduce performance and diminish transparency. We recommend deleting these groups.

Groups without members could be system groups. These should not be deleted.


Step-by-step process

  1. Select Dashboard.
  2. Double-click Empty groups.


  1. Access Rights Manager automatically switches to "Multiselection".
  2. The scenario "Empty groups" is active. All listed groups are empty.
  3. (Multi-) Select the groups that you know are safe to delete.
  4. Right-click and select "Delete accounts" from the context menu.


  1. Optional: Change the login used to delete the groups in the AD.
  2. Recommended: Activate the option Remove access rights and prevent the occurance of unresolved SIDs.


  1. Choose whether to run a script before deleting. See also: Configure scripts
  2. You must enter a comment.
  3. Start the deletion process.