Searching for Deleted Objects
Using a graphical user interface
Using a command-line interface
To view all of the deleted objects in the current domain, use the following syntax:
> adfind -default -rb "cn=Deleted Objects" -showdel
It is currently not possible to search for deleted objects with ADSI or ADO.
When an object is deleted in Active Directory, it is not completely deleted. The original object is renamed, most of its attributes are cleared, and it is moved to the Deleted Objects container within the naming context that it was deleted from. See the "Introduction" in this chapter for more on tombstone objects.
Both the Deleted Objects container and tombstone objects themselves are hidden by default in tools such as ADUC and ADSI Edit. To query tombstone objects, you need to enable the Return Deleted Objects LDAP control, which has an OID of 1.2.840. 1135188.8.131.527. When that control is enabled, you can perform searches for tombstone objects by specifying a search filter that contains (isDeleted=TRUE) in it. Only members of the administrator groups can perform searches for tombstone objects.
MSDN: Retrieving Deleted Objects