Different applications work with AD accounts differently. Some tie them to the SID of the user account. In which case the new account account created in AD would appear as completely different user to the application. Other application link to the user based on the domain\username. Deleting and recreating accounts in AD wouldn’t make a difference to these applications if the new user retains the same logon name. My suggestion would be to remove the user from the application, and recreate their account inside that application and then applying the permissions they need.