Emergency server help: get in touch

Enable and use the Active Directory Recycle Bin to restore deleted objects

How to switch on the Active Directory Recycle Bin, restore deleted users, groups and computers with Restore-ADObject or the Administrative Center, recover an entire deleted OU in the right order, and what to do when the Recycle Bin was never enabled.

Published Updated 5 min read

Deleting the wrong OU in Active Directory used to mean an authoritative restore from a system state backup, a Directory Services Restore Mode reboot and a long evening. The Active Directory Recycle Bin keeps deleted objects intact, with their SIDs, group memberships and attributes, for the length of the deleted object lifetime (180 days by default) so they can be restored in seconds. It is still not enabled by default on a new forest, even on Windows Server 2025, so it belongs at the top of the checklist for any domain you inherit.

Applies to Forests at Windows Server 2008 R2 functional level or higher, including Windows Server 2025

Short answer: With the forest at Windows Server 2008 R2 functional level or higher, run Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target corp.example.com once as an Enterprise Admin; it cannot be turned off again. To restore, find the object with Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "jsmith*"' -IncludeDeletedObjects and pass it to Restore-ADObject, or use the Deleted Objects container in the Active Directory Administrative Center. Restore parent OUs before their children or the restore fails.

Check prerequisites and enable it

The forest functional level must be at least Windows Server 2008 R2:

Get-ADForest | Select-Object ForestMode, RootDomain
Get-ADOptionalFeature -Filter * | Select-Object Name, EnabledScopes

If EnabledScopes for “Recycle Bin Feature” is empty, enable it from any DC as a member of Enterprise Admins:

Enable-ADOptionalFeature -Identity 'Recycle Bin Feature' `
  -Scope ForestOrConfigurationSet -Target 'corp.example.com' -Confirm:$false

The change is forest-wide and permanent. It replicates to every DC and takes effect once replication converges; objects deleted before enabling it are not recoverable this way because they were already stripped to tombstones. The same switch is available in the Active Directory Administrative Center by selecting the domain in the left pane and choosing “Enable Recycle Bin” from the Tasks pane. If the level is too low, see raise the AD forest and domain functional level safely.

Restore a single object

Search the Deleted Objects container, which is hidden from normal queries:

Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Jane Smith*"' `
  -IncludeDeletedObjects -Properties LastKnownParent, whenChanged |
  Select-Object Name, ObjectClass, LastKnownParent, whenChanged

Restore it to its original location, or to a new one if the parent OU no longer exists:

Get-ADObject -Filter 'SamAccountName -eq "jsmith"' -IncludeDeletedObjects | Restore-ADObject
Restore-ADObject -Identity "<objectGUID>" -TargetPath "OU=Staff,DC=corp,DC=example,DC=com"

The restored user keeps the same SID, password, group memberships and attributes, so file permissions and mailboxes reconnect without any further work. Computer accounts restore the same way and rejoin the domain transparently, which is the right fix for a machine whose object was deleted by mistake rather than rejoining it.

Restore a deleted OU and its contents

When an entire OU is deleted, its children are deleted with it and each keeps a LastKnownParent pointing at the OU. Restore in parent-first order:

$deleted = Get-ADObject -Filter 'isDeleted -eq $true -and LastKnownParent -like "*OU=Sales*"' `
  -IncludeDeletedObjects -Properties LastKnownParent
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Sales*" -and ObjectClass -eq "organizationalUnit"' -IncludeDeletedObjects | Restore-ADObject
$deleted | Where-Object ObjectClass -eq 'organizationalUnit' | Restore-ADObject
$deleted | Where-Object ObjectClass -ne 'organizationalUnit' | Restore-ADObject

For nested OUs, sort by the length of the distinguished name so shallower objects go first. The Administrative Center makes this easier: open Deleted Objects, filter by name, select the OU and choose Restore, then repeat for the contents, which will now show their original parent as available.

Protect against the next accident

The Recycle Bin is a safety net, not a substitute for prevention or backups. Tick “Protect object from accidental deletion” on every OU (it is on by default for new OUs but not for those created by scripts), and set it in bulk:

Get-ADOrganizationalUnit -Filter * | Set-ADObject -ProtectedFromAccidentalDeletion $true

Keep system state backups of at least two DCs, because the Recycle Bin cannot help with schema damage, a corrupted database or a deletion older than the lifetime. If you need a longer retention, raise msDS-DeletedObjectLifetime on CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=corp,DC=example,DC=com with Set-ADObject, keeping it at or below the tombstone lifetime.

Verify

After enabling, Get-ADOptionalFeature 'Recycle Bin Feature' should list the forest’s configuration partition under EnabledScopes on every DC. Test it once by creating a throwaway user, deleting it, and restoring it with Restore-ADObject; the user should reappear with the same objectSID. A common pitfall is searching with Get-ADUser, which never returns deleted objects; use Get-ADObject with -IncludeDeletedObjects every time.

Active Directory Recycle Bin at a glance

Enable and use the Active Directory Recycle Bin to restore d summary card: With the forest at Windows Server 2008 R2 functional level or higher, run Enable-ADOptionalFeature 'Recycle Bin…
In short: With the forest at Windows Server 2008 R2 functional level or higher, run Enable-ADOptionalFeature ‘Recycle Bin Feature’ -Scope ForestOrConfigurationSet -Target corp.example.com once as an Enterprise Admin; it cannot be turned off again.

Official documentation: Active Directory Domain Services docs, Windows Server documentation.

Related guides: Set up a file server with DFS Namespaces and DFS Replication · How to find the source of Active Directory account lockouts (Event ID 4740) · Configure NTP time sync for the PDC emulator and domain clients.

Frequently asked questions

Does the Active Directory Recycle Bin also restore group memberships?

Yes; because objects are preserved with all linked attributes, a restored user regains every group it was a member of, and a restored group regains its members, as long as those objects still exist.

How long do deleted objects stay in the Recycle Bin?

For the deleted object lifetime, which defaults to 180 days (or the tombstone lifetime on older forests); after that the object becomes a recycled tombstone and can only be recovered from a backup.

Can I disable the Recycle Bin after enabling it?

No; enabling the feature is permanent for the forest, and the only reversal is a full forest recovery, so plan for the slightly larger database and enable it once.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Forests at Windows Server 2008 R2 functional level or higher, including Windows Server 2025
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.