Hello Eric Johnson,
Thank you for posting in Q&A forum.
Based on the description, I understand that the Keys and Managed Service Accounts containers have been deleted for a long time, and the Active Directory Recycle Bin was enabled before the Keys and Managed Service Accounts containers were deleted.
Now you want to restore the Keys and Managed Service Accounts containers.
1.If the time is no longer than 180 days. Please check if you can see the Keys and Managed Service Accounts containers via ADAC (Active Directory Administrative Center).
Open ADAC and navigate to domain.com\Deleted Objects container, open Deleted Objects container to see if there is the Keys and Managed Service Accounts containers.
If so, you can right click them and restore them.
- If the two containers cannot be restored by ADAC. Please check whether you have a backup of one Domain Controller with the two containers (Keys and Managed Service Accounts).
If you have such Domain Controller backup with the two containers (Keys and Managed Service Accounts). You can perform a nonauthoritative restore of this Domain Controller, after nonauthoritative restore of this Domain Controller is complete, please wait to AD replication finish, then you can perform a authoritative restore of the two containers (Keys and Managed Service Accounts).
For more information, please refer to links below.
Active Directory Forest Recovery - Perform a nonauthoritative restore of Active Directory Domain Services
I hope the information above is helpful.
If you have any questions or concerns, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.