Description
Key Vault soft delete keeps deleted vaults and objects recoverable during a retention period. It is enabled by default for new vaults and cannot be disabled after activation. Purge protection is a separate setting that prevents permanent deletion before retention expires.
With soft delete alone, an identity with purge permission can still permanently delete an object during retention. Purge protection cannot be turned off once enabled, so review the retention policy and recovery requirements together.
Potential impact
- Permanent deletion of a key, secret or certificate can interrupt dependent services or make encrypted data inaccessible.
- Missing recovery procedures can delay service restoration after deletion.
Remediation
- Verify actual soft-delete protection and set
enablePurgeProtection: true. Choose a retention period of 7–90 days at creation; it cannot be changed afterward. - Limit delete, purge and recovery permissions and test recovery procedures. Purge protection does not replace backups or access controls.
- After restoring a vault, check integrations such as RBAC role assignments and Event Grid subscriptions, and recreate them where needed.
Examples
Supply a unique vaultName. These examples use Azure RBAC, so configure required data role assignments separately. Review deployment, disk-encryption and network-access settings for the actual use case as well.
Before
param vaultName string
resource keyVaultInstance 'Microsoft.KeyVault/vaults@2019-09-01' = {
name: vaultName
location: resourceGroup().location
tags: {}
properties: {
tenantId: subscription().tenantId
sku: {
family: 'A'
name: 'standard'
}
accessPolicies: []
enabledForDeployment: true
enabledForDiskEncryption: true
enabledForTemplateDeployment: true
enableSoftDelete: true
softDeleteRetentionInDays: 80
enableRbacAuthorization: true
}
}
Soft delete is enabled, but purge protection is not specified. Purge protection is not enabled by default on a new vault.
After
param vaultName string
resource keyVaultInstance 'Microsoft.KeyVault/vaults@2019-09-01' = {
name: vaultName
location: resourceGroup().location
tags: {}
properties: {
tenantId: subscription().tenantId
sku: {
family: 'A'
name: 'standard'
}
accessPolicies: []
enabledForDeployment: true
enabledForDiskEncryption: true
enabledForTemplateDeployment: true
enableSoftDelete: true
softDeleteRetentionInDays: 80
enableRbacAuthorization: true
enablePurgeProtection: true
}
}
Purge protection prevents permanently deleting a deleted object before the 80-day retention period expires. It does not prevent the initial deletion.