Description
Key Vault soft delete allows deleted vaults, keys, secrets, and certificates to be recovered within the retention period. It is enabled by default for new vaults and cannot be disabled once enabled.
Potential impact
Legacy configurations without recovery protection can allow deletion to cause permanent loss and service disruption. Even with soft delete, an authorized principal can purge an object early unless purge protection is also enabled.
Remediation
Check the vault’s actual soft-delete setting and remove obsolete settings that attempt to disable it. Configure purge protection when permanent deletion must be prevented throughout retention.
Examples
The initial enable_soft_delete: no value is a legacy setting to remove, not a way to disable protection on an enabled vault. SKU and access settings are omitted.
Before
- name: Key Vault 생성
azure_rm_keyvault:
resource_group: myResourceGroup
vault_name: samplekeyvault
enabled_for_deployment: yes
enable_soft_delete: no
vault_tenant: 72f98888-8666-4144-9199-2d7cd0111111
After
- name: Key Vault 생성
azure_rm_keyvault:
resource_group: myResourceGroup
vault_name: samplekeyvault
enabled_for_deployment: yes
enable_soft_delete: yes
vault_tenant: 72f98888-8666-4144-9199-2d7cd0111111