When devices are removed from domain, the device is also synced with the PAm appliance, thus removing the device and the password history of the local account. When a device needs to be restored the password that was rotated by PAM is not retrievable anymore. If PAM had a retention policy for all the passwords it manages, also if the device or object was removed. This would be great
What you request is not a feature of PAM. As you stated, when the device is removed the history related to it is also removed. If you would like to see such a feature enabled for PAM you will have to make an Enhancement Request, by creating an Idea in the PAM Community. Posting the request here is not the correct path.