4.2 Deleting Groups in eDirectory

If you want to delete a group from eDirectory and ensure that the corresponding RACF group is not used until you can schedule the RACF Remove ID utility, remove each user from the Group object's Member list before you delete it.

Because the RACF DELGROUP command does not clean up references to a group from such places as resource access lists, and cannot be used to delete a universal group, the Subscriber Event policy vetoes delete commands for Group objects. IBM recommends that you use the RACF Remove ID utility (IRRRID00) when deleting groups. For more information, see your Security Server RACF Security Administrators Guide.