How do I get the current status of the Active Directory Recycle Bin?

A quick refresher on the Active Directory Recycle Bin:

  • Requires a Forest Functional Level of Windows Server 2008 R2 (or above)
  • Needs to be enabled (use the enable-adoptionalfeature cmdlet in PowerShell, or use the GUI in the Active Directory Administrative Center)

 

What it gives you (in summary), is extended time with which to recover objects that have been deleted from the “visible” Active Directory.  So with the Recycle Bin enabled, the default lifespan of a deleted item is 180 days (Deleted Object Lifetime); after which, the object is tombstoned and not recoverable by the Recycle Bin feature. After an additional 180 days (Tombstone Lifetime), the object is physically deleted from the database.

Graphically, it looks like this:

 

And here’s a quick bit of code that will tell you the current state of your Forest Functional Level, if the Recycle Bin is enabled, and if so, which DCs it has been successfully applied to (it should be all of them – if it’s not, you have a problem).

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *