We have (mostly yearly) the problem that organizational groups are renamed in Active Directory (department names are changing etc.) and the impact is that a lot of group names in Confluence also changes (= old groups are removed, new groups are created and memberships added). In all spaces where this groups are permitted the permissions are broken. How can this be avoided or worked around?