AD-FOR-04 - Recycle Bin status should be retrievable
Overviewβ
The Active Directory Recycle Bin provides significant advantages over traditional tombstone reanimation:
- Complete Object Recovery: Restores all object attributes, group memberships, and links
- Simplified Recovery: No need to restore from backup for accidental deletions
- Reduced Downtime: Faster recovery of critical objects
- Attribute Preservation: Unlike tombstone reanimation, all attributes are preserved
Requirements:
- Forest functional level of Windows Server 2008 R2 or higher
- Must be explicitly enabled (not enabled by default)
Security Recommendationβ
Enable the Recycle Bin if your forest functional level supports it:
Enable-ADOptionalFeature -Identity "Recycle Bin Feature" -Scope ForestOrConfigurationSet -Target "yourforest.com"
Important Considerations:
- Irreversible: Once enabled, the Recycle Bin cannot be disabled
- Database Size: Increases AD database size due to preserved objects
- Tombstone Lifetime: Objects are retained for the tombstone lifetime period
- Planning: Ensure adequate disk space and backup strategies
How the Test Worksβ
This test checks the optional features in Active Directory to determine if the Recycle Bin Feature is enabled and reports its status.
Related Testsβ
Test-MtAdTombstoneLifetime- Retrieves the tombstone lifetime (affects Recycle Bin retention)Test-MtAdForestFunctionalLevel- Retrieves the forest functional level (required for Recycle Bin)
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-FOR-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdRecycleBinStatus |
| Tags | AD, AD-FOR-04, AD.Forest |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdRecycleBinStatus.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdRecycleBinStatus.ps1

