# Enable and use the Active Directory Recycle Bin to restore deleted objects

Source: https://srvscripts.com/guides/enable-active-directory-recycle-bin/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

Deleting the wrong OU in Active Directory used to mean an authoritative restore from a system state backup, a Directory Services Restore Mode reboot and a long evening. The Active Directory Recycle Bin keeps deleted objects intact, with their SIDs, group memberships and attributes, for the length of the deleted object lifetime (180 days by default) so they can be restored in seconds. It is still not enabled by default on a new forest, even on Windows Server 2025, so it belongs at the top of the checklist for any domain you inherit.

In short: With the forest at Windows Server 2008 R2 functional level or higher, run Enable-ADOptionalFeature ‘Recycle Bin Feature’ -Scope ForestOrConfigurationSet -Target corp.example.com once as an Enterprise Admin; it cannot be turned off again.

**Short answer:** With the forest at Windows Server 2008 R2 functional level or higher, run `Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target corp.example.com` once as an Enterprise Admin; it cannot be turned off again. To restore, find the object with `Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "jsmith*"' -IncludeDeletedObjects` and pass it to `Restore-ADObject`, or use the Deleted Objects container in the Active Directory Administrative Center. Restore parent OUs before their children or the restore fails.

## Check prerequisites and enable it

The forest functional level must be at least Windows Server 2008 R2:

```
Get-ADForest | Select-Object ForestMode, RootDomain
Get-ADOptionalFeature -Filter * | Select-Object Name, EnabledScopes
```

If EnabledScopes for “Recycle Bin Feature” is empty, enable it from any DC as a member of Enterprise Admins:

```
Enable-ADOptionalFeature -Identity 'Recycle Bin Feature' `
  -Scope ForestOrConfigurationSet -Target 'corp.example.com' -Confirm:$false
```

The change is forest-wide and permanent. It replicates to every DC and takes effect once replication converges; objects deleted before enabling it are not recoverable this way because they were already stripped to tombstones. The same switch is available in the Active Directory Administrative Center by selecting the domain in the left pane and choosing “Enable Recycle Bin” from the Tasks pane. If the level is too low, see [raise the AD forest and domain functional level safely](/guides/raise-ad-functional-level/).

## Restore a single object

Search the Deleted Objects container, which is hidden from normal queries:

```
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Jane Smith*"' `
  -IncludeDeletedObjects -Properties LastKnownParent, whenChanged |
  Select-Object Name, ObjectClass, LastKnownParent, whenChanged
```

Restore it to its original location, or to a new one if the parent OU no longer exists:

```
Get-ADObject -Filter 'SamAccountName -eq "jsmith"' -IncludeDeletedObjects | Restore-ADObject
Restore-ADObject -Identity "" -TargetPath "OU=Staff,DC=corp,DC=example,DC=com"
```

The restored user keeps the same SID, password, group memberships and attributes, so file permissions and mailboxes reconnect without any further work. Computer accounts restore the same way and rejoin the domain transparently, which is the right fix for a machine whose object was deleted by mistake rather than rejoining it.

## Restore a deleted OU and its contents

When an entire OU is deleted, its children are deleted with it and each keeps a LastKnownParent pointing at the OU. Restore in parent-first order:

```
$deleted = Get-ADObject -Filter 'isDeleted -eq $true -and LastKnownParent -like "*OU=Sales*"' `
  -IncludeDeletedObjects -Properties LastKnownParent
Get-ADObject -Filter 'isDeleted -eq $true -and Name -like "Sales*" -and ObjectClass -eq "organizationalUnit"' -IncludeDeletedObjects | Restore-ADObject
$deleted | Where-Object ObjectClass -eq 'organizationalUnit' | Restore-ADObject
$deleted | Where-Object ObjectClass -ne 'organizationalUnit' | Restore-ADObject
```

For nested OUs, sort by the length of the distinguished name so shallower objects go first. The Administrative Center makes this easier: open Deleted Objects, filter by name, select the OU and choose Restore, then repeat for the contents, which will now show their original parent as available.

## Protect against the next accident

The Recycle Bin is a safety net, not a substitute for prevention or backups. Tick “Protect object from accidental deletion” on every OU (it is on by default for new OUs but not for those created by scripts), and set it in bulk:

```
Get-ADOrganizationalUnit -Filter * | Set-ADObject -ProtectedFromAccidentalDeletion $true
```

Keep system state backups of at least two DCs, because the Recycle Bin cannot help with schema damage, a corrupted database or a deletion older than the lifetime. If you need a longer retention, raise `msDS-DeletedObjectLifetime` on `CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=corp,DC=example,DC=com` with `Set-ADObject`, keeping it at or below the tombstone lifetime.

## Verify

After enabling, `Get-ADOptionalFeature 'Recycle Bin Feature'` should list the forest’s configuration partition under EnabledScopes on every DC. Test it once by creating a throwaway user, deleting it, and restoring it with `Restore-ADObject`; the user should reappear with the same objectSID. A common pitfall is searching with `Get-ADUser`, which never returns deleted objects; use `Get-ADObject` with `-IncludeDeletedObjects` every time.

## Active Directory Recycle Bin at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Set up a file server with DFS Namespaces and DFS Replication](https://srvscripts.com/guides/dfs-namespaces-and-replication/) · [How to find the source of Active Directory account lockouts (Event ID 4740)](https://srvscripts.com/guides/ad-account-lockout-source-event-4740/) · [Configure NTP time sync for the PDC emulator and domain clients](https://srvscripts.com/guides/pdc-emulator-ntp-time-sync/).

## Frequently asked questions

### Does the Active Directory Recycle Bin also restore group memberships?

Yes; because objects are preserved with all linked attributes, a restored user regains every group it was a member of, and a restored group regains its members, as long as those objects still exist.

### How long do deleted objects stay in the Recycle Bin?

For the deleted object lifetime, which defaults to 180 days (or the tombstone lifetime on older forests); after that the object becomes a recycled tombstone and can only be recovered from a backup.

### Can I disable the Recycle Bin after enabling it?

No; enabling the feature is permanent for the forest, and the only reversal is a full forest recovery, so plan for the slightly larger database and enable it once.
