Using Vmover.exe to reACL a share located on a SAN with /volume command line option, practically adds the matching target user/group to the ACL, and retains the source object with the same access rights. How one can remove the source accounts at the end of the migration? To the best of my understanding, not doing so and de-commissioning the source domain (or deleting the source objects) will leave orphaned SIDs on the share - and this is not nice.
P.S. my experience till now, is that "adding" the target account is the standard functionality with the vmover.ini. I suspect that an option in vmover.ini possibly controls the functionality I am after, however not all options in vmover.ini are fully documented.