Resource with an AD group entitlement that gets relocated in the tree

We are provisioning a resource where the AD group entitlement has been relocated. It's been moved to a different OU. The group entitlement is still being provisioned correctly because it looks like Identity Manager is using the GUID to locate the group, not the DN.The resource's nrfEntitlementRef value still contains the old DN. So do the dirXML-entitlement attributes on the user objects. 

Is this fine to leave as is or should I create a new resource with the new entitlement DN? It's a fairly large role and the processing will cause downtime for end users so I am trying to avoid creating a new resource unless necessary.