Active directory recycle bin is a feature introduced with windows server 2008 R2 to undo or recover a deletion of an Active directory object. With windows server 2012 R2, you can use this feature to recover User objects, Computer objects or Organizational groups when you accidentally or purposefully deleted from the Active directory.
The Feature is rather improved, now it’s a part of the Active Directory administration center. So it’s not required to use PowerShell commands when recovering. AD Administration center has a GUI, which can be used to easily locate a deleted item, and from one click you can restore it to the original location. This is a very useful feature in day to day operations and let’s see how we can enable this.
Enabling AD Recycle Bin
Before enabling this feature you have to check whether your AD functional level is supported. You have to have minimum Windows server 2008R2 Forest functional level or higher. And it’s irreversible, once you have enable it you cannot disable. Also you need to aware that size of the NTDS database will be increase after you enabled the recycle bin. It will keep the deletion data and with time it will increase more, so I suggest you to delete unnecessary data from the bin time to time. Enterprise admin rights are required to access the recycle bin.
How to restore an object
To test the configurations, let’s create a test account, delete it and check how to restore it using the Administrative center.
Right click and select restore
AD Recycle Bin is a useful tool in day to day operations. It will minimize the risk of the operation. You can delegate user operations to the help desk or junior staff, so if they make any mistake you have the option to correct it. Hope this post is useful
Cheers
Asitha De Silva