On Redhat 5 and 6 we could empty the ldap cache with this command: nscd -i group and nscd -i netgroup But in Redhat 7 this doesn’t work. Instead one have to run this command: sss_cache -E here is more about sss_cache from Redhat: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/deployment_guide/sssd-cache