Deleting the wrong OU in Active Directory used to mean an authoritative restore from a system state backup, a Directory Services Restore Mode reboot and a long evening. The Active Directory Recycle Bin keeps deleted objects intact, with their SIDs, group memberships and attributes, for the length of the deleted object lifetime (180 days by default) so they can be restored in seconds. It is still not enabled by default on a new forest, even on Windows Server 2025, so it belongs at the top of the checklist for any domain you inherit.
Applies to Forests at Windows Server 2008 R2 functional level or higher, including Windows Server 2025
Table of Contents
Short answer: With the forest at Windows Server 2008 R2 functional level or higher, run Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target corp.example.com once as an Enterprise Admin; it cannot be turned off again. To restore, find the object with Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "jsmith*"' -IncludeDeletedObjects and pass it to Restore-ADObject, or use the Deleted Objects container in the Active Directory Administrative Center. Restore parent OUs before their children or the restore fails.
Check prerequisites and enable it
The forest functional level must be at least Windows Server 2008 R2:
Get-ADForest | Select-Object ForestMode, RootDomain
Get-ADOptionalFeature -Filter * | Select-Object Name, EnabledScopes
If EnabledScopes for “Recycle Bin Feature” is empty, enable it from any DC as a member of Enterprise Admins:
Enable-ADOptionalFeature -Identity 'Recycle Bin Feature' `
-Scope ForestOrConfigurationSet -Target 'corp.example.com' -Confirm:$false
The change is forest-wide and permanent. It replicates to every DC and takes effect once replication converges; objects deleted before enabling it are not recoverable this way because they were already stripped to tombstones. The same switch is available in the Active Directory Administrative Center by selecting the domain in the left pane and choosing “Enable Recycle Bin” from the Tasks pane. If the level is too low, see raise the AD forest and domain functional level safely.
Restore a single object
Search the Deleted Objects container, which is hidden from normal queries:
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Jane Smith*"' `
-IncludeDeletedObjects -Properties LastKnownParent, whenChanged |
Select-Object Name, ObjectClass, LastKnownParent, whenChanged
Restore it to its original location, or to a new one if the parent OU no longer exists:
Get-ADObject -Filter 'SamAccountName -eq "jsmith"' -IncludeDeletedObjects | Restore-ADObject
Restore-ADObject -Identity "<objectGUID>" -TargetPath "OU=Staff,DC=corp,DC=example,DC=com"
The restored user keeps the same SID, password, group memberships and attributes, so file permissions and mailboxes reconnect without any further work. Computer accounts restore the same way and rejoin the domain transparently, which is the right fix for a machine whose object was deleted by mistake rather than rejoining it.
Restore a deleted OU and its contents
When an entire OU is deleted, its children are deleted with it and each keeps a LastKnownParent pointing at the OU. Restore in parent-first order:
$deleted = Get-ADObject -Filter 'isDeleted -eq $true -and LastKnownParent -like "*OU=Sales*"' `
-IncludeDeletedObjects -Properties LastKnownParent
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Sales*" -and ObjectClass -eq "organizationalUnit"' -IncludeDeletedObjects | Restore-ADObject
$deleted | Where-Object ObjectClass -eq 'organizationalUnit' | Restore-ADObject
$deleted | Where-Object ObjectClass -ne 'organizationalUnit' | Restore-ADObject
For nested OUs, sort by the length of the distinguished name so shallower objects go first. The Administrative Center makes this easier: open Deleted Objects, filter by name, select the OU and choose Restore, then repeat for the contents, which will now show their original parent as available.
Protect against the next accident
The Recycle Bin is a safety net, not a substitute for prevention or backups. Tick “Protect object from accidental deletion” on every OU (it is on by default for new OUs but not for those created by scripts), and set it in bulk:
Get-ADOrganizationalUnit -Filter * | Set-ADObject -ProtectedFromAccidentalDeletion $true
Keep system state backups of at least two DCs, because the Recycle Bin cannot help with schema damage, a corrupted database or a deletion older than the lifetime. If you need a longer retention, raise msDS-DeletedObjectLifetime on CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=corp,DC=example,DC=com with Set-ADObject, keeping it at or below the tombstone lifetime.
Verify
After enabling, Get-ADOptionalFeature 'Recycle Bin Feature' should list the forest’s configuration partition under EnabledScopes on every DC. Test it once by creating a throwaway user, deleting it, and restoring it with Restore-ADObject; the user should reappear with the same objectSID. A common pitfall is searching with Get-ADUser, which never returns deleted objects; use Get-ADObject with -IncludeDeletedObjects every time.
Active Directory Recycle Bin at a glance

Official documentation: Active Directory Domain Services docs, Windows Server documentation.
Related guides: Set up a file server with DFS Namespaces and DFS Replication · How to find the source of Active Directory account lockouts (Event ID 4740) · Configure NTP time sync for the PDC emulator and domain clients.
Frequently asked questions
Does the Active Directory Recycle Bin also restore group memberships?
Yes; because objects are preserved with all linked attributes, a restored user regains every group it was a member of, and a restored group regains its members, as long as those objects still exist.
How long do deleted objects stay in the Recycle Bin?
For the deleted object lifetime, which defaults to 180 days (or the tombstone lifetime on older forests); after that the object becomes a recycled tombstone and can only be recovered from a backup.
Can I disable the Recycle Bin after enabling it?
No; enabling the feature is permanent for the forest, and the only reversal is a full forest recovery, so plan for the slightly larger database and enable it once.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Forests at Windows Server 2008 R2 functional level or higher, including Windows Server 2025
- Last full review
- Next review