After you delete an object it will become a tombstone in AD within the
deleted objects container. When an object is deleted values from all
attributes from the object will be stripped and removed (except for system
attributes like "objectGUID", "objectSid", "distinguishedName",
"nTSecurityDescriptor" and "uSNChanged" which are preserved on the
tombstone) (On W2K3 SP1 DCs, the "sIDHistory" attribute is also preserved)
The tombstone is preserved for the period of the tombstone lifetime which is
for:
Fresh install of AD with W2K DCs (all SPs): 60 days
Upgrading AD with W2K DCs to W2K3 DCs: 60 days
Upgrading AD with W2K DCs to W2K3 SP1 DCs: 60 days
Fresh install of AD with W2K3 DCs (all SPs): 60 days
Upgrading AD with W2K3 DCs to W2K3 SP1 DCs: 60 days
Fresh install of AD with W2K3 SP1 DCs (all SPs): 180 days
In both W2K and W2K3 AD you can perform an authoritative restore of the
object using a system state backup that still contains the object and is not
older than the period of the tombstone lifetime . Doing it this way will
restore the object and its attributes
Only in W2K3 AD you can reanimate the tombstone to a live object again. Free
third party utilities (sysinternals, quest) exist that do not repopulate the
attribtues and non-free third party utilities (Netpro RestoreADmin and Quest
Recovery Manager) are available that can undelete/reanimate and repopulate
the attributes