A directory server topology could be quite complex and it could happen that deleted entries are resurrected due to replication conflicts.
Those entries are marked with:
– the “glue” and “extensibleObject” objectclass
– the “nsds5ReplConflict” attribute
You may need to filter those entries, and the suggested way is to use an ACI, as suggested in the official documentation.