Activate the new AD recycle bin feature for no-cost additional protection. Prepare for the big OOPS.
Prior to Windows Server 2008 R2, the ability to recover deleted objects existed, but it usually required taking a DC offline and performing multiple authoritative restores, leaving the object stripped of most attribute details. With Windows Server 2008 R2, you can enable and leverage the AD Recycle Bin to restore AD objects with all attributes in their entirety to the same state they were in just prior to deletion. This includes group membership. Using the recycle bin feature can help reduce directory services downtime by improving your ability to recover accidentally deleted AD objects without many of the previous challenges and deficiencies.