Double contacts (sso and ldap) - how to clean up contacts-db?

nextcloud 31.0.14

some years ago we started with authenticating towards our local AD via ldap-backend.

some time ago we added an SSO-login (entraID) which works fine. for both systems we used samaccountname as identifier to map both technical accounts to one user.

login works fine, but when sharing something within nextcloud a user is shown twice. i guess one is from SSO-login, and the other is from the LDAP-backend. we already disabled the ldap-sync for users (only some groups were still needed).

is there any way to remove “wrong” users from the sharing-contacts?

kind regards,

andre