Getting closer to the Active Directory Recycle Bin for free

Active Directory

I just posted that in R2 Microsoft plans to provide a true Recycle Bin for AD objects that were deleted, but until then the best we've got is Windows Server 2008 Active Directory.

After hours of researching “how do AD snapshots in 2008 help me recover a deleted object(s), it’s attributes, and referring objects (i.e. groups pointing back to the deleted user)?” I was disappointed.

From what I can tell, the answer is: built in tools allow for no additional automation over 2003 AD, other than using cut and paste to restore attributes from the snapshot to live AD (after you’ve reanimated the object in live AD).

You may be able to mount AD snapshots, and even view them with Users and Computers and other AD tools, but you really can't DO ANYTHING with that data  So I went searching for how others were solving this.

Here’s one of a few tools that tries to automate the process of finding the tombstoned object in your live AD, find it’s old info in a snapshot, and dumping that data back in to the reanimated object in AD:

Jorge from dirteam.com talks about it, basically describing my realization in greater detail