To set up Active Directory object recovery, the following steps should be taken:
- Enable the Tombstone Reanimation feature in the domain environment
- Run the repadmin.exe command to delete all Tomsbtone objects
- Create an empty, non-administrative account in AD
- Set the expiry policy for recovered objects
- Configure AD cryptocurrencies for additional security