Implications of Enabling Recycle Bin Feature in Active Directory

active-directorywindows-server-2008-r2

An admin accidentally deleted the wrong OU and it removed several account and computer objects. The recycle bin optional feature was not enabled. We used adrestore from sysinternals to get the accounts back.

To ensure this process is easier the next time we wanted to enable the Recycle Bin optional feature which is easily done as per guides and TechNet using Enable-ADOptionalFeature via PowerShell.

In both PowerShell and the above link the following is mentioned.

In this release of Windows Server 2008 R2, the process of enabling Active Directory Recycle Bin is irreversible. After you enable Active Directory Recycle Bin in your environment, it cannot be disabled.

In theory I would always want to leave it enabled but I have hesitated until I understand the implication of what is about to happen. I have a single domain forest if it matters.

What is the implication of enabled this feature? This must relate to why it is not enabled by default.

Best Answer

The main implication of enabling this feature is that it will increase the size of your DIT. (Your database.) It tends to increase the size because objects that have been deleted hang around longer than they would without the AD Recycle Bin enabled.

Related Topic