Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with Active Directory Recycle Bin if it was enabled before the deletion and the deleted-object lifetime has not expired. In Active Directory Administrative Center, open the domain’s Deleted Objects container and restore the item, or use PowerShell’s Get-ADObject -IncludeDeletedObjects with Restore-ADObject. Recycle Bin preserves link-valued and non-link-valued attributes, including group memberships, so the object returns to the consistent logical state it had immediately before deletion. If Recycle Bin was unavailable, restore a domain controller system-state backup and perform a narrowly scoped authoritative restore with ntdsutil.

Choose the recovery method before changing anything

The correct procedure depends on five facts: whether Recycle Bin was enabled before deletion, how much time has passed, whether a suitable system-state backup exists, how broad a restore is required, and how much collateral rollback your organization can accept.

Situation Preferred method State retained Main risk or limit
Recycle Bin was enabled before the deletion and the object is still within the applicable lifetime AD Administrative Center or Restore-ADObject Link-valued and non-link-valued attributes, including memberships It cannot restore objects deleted before Recycle Bin was enabled or after garbage collection
Recycle Bin was not enabled, but a valid domain-controller system-state backup exists Narrowly scoped authoritative restore with ntdsutil The data contained in the selected backup and restore scope Newer changes inside the restored scope can be rolled back
The object has passed garbage collection and no suitable backup exists Specialized recovery process or recovery software Depends on the available system and backup data Native Active Directory undelete is no longer available

Do not begin with a whole-directory or whole-subtree restore when a single-object Recycle Bin restore will solve the problem. A broader authoritative restore can change passwords, profile paths, contact data, memberships and security descriptors that were updated after the backup.

Restore with Active Directory Recycle Bin

Confirm that Recycle Bin can help

  • The feature must have been enabled before the deletion. Enabling it now does not recover earlier deletions.
  • The object must still be inside the configured deleted-object lifetime and must not have been removed by garbage collection.
  • You need administrative rights appropriate to your environment and a management workstation or server with RSAT, AD Administrative Center (ADAC), or the Active Directory PowerShell module.

When Recycle Bin is available, it preserves the object’s link-valued and non-link-valued attributes. That is why it is normally safer than replaying an older directory backup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use AD Administrative Center

  1. Sign in with an account authorized to restore the object.
  2. Open Active Directory Administrative Center.
  3. Select the domain, then open the Deleted Objects container.
  4. Locate the deleted user, group, computer, organizational unit (OU), or other object. Verify its identity, object class and former distinguished name.
  5. Choose Restore. If the original parent container no longer exists or you intentionally want another location, use the option to restore to a different container when it is offered.
  6. After replication, verify the object’s distinguished name, enabled state, group memberships and other business-critical attributes.

Restore with PowerShell

Run the Active Directory module from a system that can query the domain. Microsoft’s example uses a name filter:

Get-ADObject -Filter 'Name -Like "*User*"' -IncludeDeletedObjects | Restore-ADObject

To place the restored objects in another OU, add -TargetPath:

Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing
Get-ADObject -Filter 'Name -Like "*User*"' -IncludeDeletedObjects | Restore-ADObject -TargetPath "OU=Corp,DC=contoso,DC=com"

The examples are intentionally broad demonstrations, not production-safe filters. In production, narrow the query to a unique identity, the expected object class and, when known, the deleted object’s distinguished name. Review the result set before piping it to Restore-ADObject; otherwise similarly named deleted objects could be restored unintentionally.

Use a two-stage PowerShell check for safer recovery

  1. List candidates without restoring them:
Get-ADObject -Filter 'Name -Like "*User*"' -IncludeDeletedObjects -Properties objectClass,lastKnownParent,whenChanged
  1. Confirm the returned object’s class, former parent and deletion timing. Then pass only the selected object to Restore-ADObject, optionally with -TargetPath.
  2. Check replication and dependent services after the restore. A restored account may still require password, logon, profile or application validation.

Enable Recycle Bin for future deletions

Enabling the feature is irreversible. The forest/domain functional level must be Windows Server 2008 R2 or higher. The operator must be a Domain Admin, and the workstation needs RSAT with ADAC or the Active Directory PowerShell module.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Confirm the functional-level requirement and obtain change approval because the operation cannot be undone.
  2. Identify the forest target and run the command from a host with the Active Directory module:
Enable-ADOptionalFeature -Identity 'CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=contoso,DC=com' -Scope ForestOrConfigurationSet -Target 'contoso.com'
  1. Replace the example distinguished name and target with your forest’s values. Verify that the feature is enabled before relying on it for a recovery plan.
  2. Document the configured deleted-object and tombstone lifetimes, and test a controlled restore so operators know the ADAC and PowerShell paths.

The feature protects only deletions that occur after activation; it is not a retroactive recovery mechanism.

When Recycle Bin was not available: authoritative restore

If Recycle Bin was disabled at the time of deletion, use a system-state backup of a domain controller and restore only the required directory scope. Coordinate the work with the domain’s replication and backup owners; authoritative restoration changes replication metadata so the restored object wins on partner domain controllers.

Restore one object

After restoring the domain controller system state and entering the appropriate directory-services recovery workflow, use the object’s full distinguished name:

ntdsutil "authoritative restore" "restore object <object DN path>" q q

Replace <object DN path> with the exact distinguished name, such as the deleted user’s or group’s DN as represented in the backup. A specific-object restore takes longer to prepare than a whole-subtree operation but is less destructive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restore a container or OU subtree

For a container and its contents, use:

ntdsutil "authoritative restore" "restore subtree <container DN path>" q q

Choose the lowest DN scope that contains the required objects. A broad subtree can roll back newer passwords, profile paths, contact information, group membership and security descriptors for every object in that scope. If a subordinate object was deleted along with its parent, the deleted parent container may also require an explicit authoritative restoration.

Understand replication after the restore

Authoritative restoration raises the restored object’s version numbers. During replication, partners therefore accept the restored copy rather than their newer tombstoned or changed copy. Plan for normal replication convergence and validate the object on multiple domain controllers before declaring recovery complete.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Lifetime limits, garbage collection and backups

Check the configured lifetimes

Active Directory’s tombstone lifetime and deleted-object lifetime determine how long deleted data remains available. These values are environment-specific; there is no single safe number to assume. Before relying on a backup, confirm that its age does not exceed the applicable tombstone lifetime, as Microsoft advises.

Know when native undelete has ended

Once garbage collection has removed the deleted object, Recycle Bin and other native undelete operations cannot bring it back. Recovery then depends on an earlier suitable system-state backup or a specialized recovery process that can work from whatever directory data remains.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Preserve evidence before repeated attempts

  • Record the object’s former distinguished name, object class, deletion time and last known parent.
  • Identify which domain controllers have received the deletion and whether replication is healthy.
  • Do not repeatedly restore broad scopes while investigating; each attempt can introduce additional rollback and replication work.
  • Capture current values of critical neighboring objects before an authoritative subtree restore so post-restore differences can be reconciled.

Post-restore verification checklist

  • Confirm the object exists on more than one domain controller after replication convergence.
  • Check the distinguished name and parent OU, especially when -TargetPath was used.
  • Verify object class, enabled or disabled state, group memberships and security-sensitive attributes.
  • For users, test an appropriate sign-in or application lookup without exposing credentials.
  • For computers and service accounts, validate trust, service bindings, SPNs and dependent applications according to your change procedure.
  • Record the recovery method, backup date, scope and any values that were intentionally rolled back.

Which method should you use?

Question If yes If no
Was Recycle Bin enabled before deletion? Search Deleted Objects and use ADAC or Restore-ADObject. Continue to a system-state backup review.
Is the deletion inside the configured deleted-object lifetime? Native Recycle Bin restoration may be possible. Check whether an earlier backup predates garbage collection.
Can you identify one object or the smallest required container? Use a specific-object restore or narrow query. Stop and identify scope before running ntdsutil.
Do you have a suitable system-state backup? Plan an authoritative restore with the least necessary DN scope. Native backup recovery is unavailable; evaluate specialized recovery options.

For repeatable operations, document unique-object filters, required permissions, lifetime settings, backup-retention coverage and verification checks. That preparation reduces the chance that an urgent account or OU deletion becomes a broad directory rollback.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.