1. user has AD+LN resources, LN depends on AD (relaxed), AD depends on LN (relaxed) with order=10
2. edit user, delete AD account, save (maybe this is problem and should not even allow)
3. stop connector server/ssh tunnel to cause Connection refused on next AD operation
4. edit user, re-add AD account, save
5. account is not created, Connection refused is reported, Shadow is created with attributes; LN account link is dropped!
6. re-start Connector Server/tunnel
7. test AD connection to repair status of the resource
8. edit user, to cause AD account to be created
As a result, user no more has LN account, which was dropped somewhere earlier.