Review Azure Key Vault soft-delete protection

Check Key Vault recovery protection and any required protection against permanent deletion.

Description

Key Vault soft delete allows deleted vaults, keys, secrets, and certificates to be recovered within the retention period. It is enabled by default for new vaults and cannot be disabled once enabled.

Potential impact

Legacy configurations without recovery protection can allow deletion to cause permanent loss and service disruption. Even with soft delete, an authorized principal can purge an object early unless purge protection is also enabled.

Remediation

Check the vault’s actual soft-delete setting and remove obsolete settings that attempt to disable it. Configure purge protection when permanent deletion must be prevented throughout retention.

Examples

The initial enable_soft_delete: no value is a legacy setting to remove, not a way to disable protection on an enabled vault. SKU and access settings are omitted.

Before

yaml
- name: Key Vault 생성
  azure_rm_keyvault:
    resource_group: myResourceGroup
    vault_name: samplekeyvault
    enabled_for_deployment: yes
    enable_soft_delete: no
    vault_tenant: 72f98888-8666-4144-9199-2d7cd0111111

After

yaml
- name: Key Vault 생성
  azure_rm_keyvault:
    resource_group: myResourceGroup
    vault_name: samplekeyvault
    enabled_for_deployment: yes
    enable_soft_delete: yes
    vault_tenant: 72f98888-8666-4144-9199-2d7cd0111111

References