Restoring objects from AD Recycle Bin
We have all been there before – a support representative calls and goes on to share that an AD object has been accidentally deleted either manually or automatically. The discussion quickly turns to raising the following questions for restoration:
- What type of AD object has been deleted and are there any attributes that might be lost due to the deletion?
- When has the object been deleted? AD garbage collection runs every 12 hours, cleaning up the AD database and any aging or tombstoned objects that have exceeded a default lifetime of 180 days, so this is important to determine during the restore request process.
- Where has the object been deleted from and to where should it be restored? The Organizational Unit (OU) is very important, as the restored object should be placed back into its original location to restore any inherited permissions, policies, or other AD attributes necessary to protect the object.
The msDS-deletedObjectLifetime...