Azure Key Vault recovery protection needs review

Review Azure Key Vault soft delete and purge protection so deleted keys, secrets and certificates remain recoverable during retention.

Description

Key Vault soft delete keeps deleted vaults and objects recoverable during a retention period. It is enabled by default for new vaults and cannot be disabled after activation. Purge protection is a separate setting that prevents permanent deletion before retention expires.

With soft delete alone, an identity with purge permission can still permanently delete an object during retention. Purge protection cannot be turned off once enabled, so review the retention policy and recovery requirements together.

Potential impact

  • Permanent deletion of a key, secret or certificate can interrupt dependent services or make encrypted data inaccessible.
  • Missing recovery procedures can delay service restoration after deletion.

Remediation

  • Verify actual soft-delete protection and set enablePurgeProtection: true. Choose a retention period of 7–90 days at creation; it cannot be changed afterward.
  • Limit delete, purge and recovery permissions and test recovery procedures. Purge protection does not replace backups or access controls.
  • After restoring a vault, check integrations such as RBAC role assignments and Event Grid subscriptions, and recreate them where needed.

Examples

Supply a unique vaultName. These examples use Azure RBAC, so configure required data role assignments separately. Review deployment, disk-encryption and network-access settings for the actual use case as well.

Before

bicep
param vaultName string

resource keyVaultInstance 'Microsoft.KeyVault/vaults@2019-09-01' = {
  name: vaultName
  location: resourceGroup().location
  tags: {}
  properties: {
    tenantId: subscription().tenantId
    sku: {
      family: 'A'
      name: 'standard'
    }
    accessPolicies: []
    enabledForDeployment: true
    enabledForDiskEncryption: true
    enabledForTemplateDeployment: true
    enableSoftDelete: true
    softDeleteRetentionInDays: 80
    enableRbacAuthorization: true
  }
}

Soft delete is enabled, but purge protection is not specified. Purge protection is not enabled by default on a new vault.

After

bicep
param vaultName string

resource keyVaultInstance 'Microsoft.KeyVault/vaults@2019-09-01' = {
  name: vaultName
  location: resourceGroup().location
  tags: {}
  properties: {
    tenantId: subscription().tenantId
    sku: {
      family: 'A'
      name: 'standard'
    }
    accessPolicies: []
    enabledForDeployment: true
    enabledForDiskEncryption: true
    enabledForTemplateDeployment: true
    enableSoftDelete: true
    softDeleteRetentionInDays: 80
    enableRbacAuthorization: true
    enablePurgeProtection: true
  }
}

Purge protection prevents permanently deleting a deleted object before the 80-day retention period expires. It does not prevent the initial deletion.

References