Check if files exist in /etc/sudoers.d/ that chef-client would not put there. If so delete them. This is necessary for the automatic cleanup of extended privileges that are not longer needed.
Of course that might destroy a number of rules that are not in chef, yet still necessary.
https://git.gsi.de is provided by CIT→Linux&Web | GSI Helmholtzzentrum fuer Schwerionenforschung GmbH | Imprint (in German) | Privacy policy