Review Azure Backup Vault immutability

Use immutability in Azure Backup Vault to reduce the risk of losing backups before their retention period expires.

Description

Vault immutability restricts operations that delete backup data before recovery points expire. Without this protection, a user with deletion permissions may accidentally or maliciously remove backups needed for recovery.

immutability = "Unlocked" enables protection but allows it to be disabled again. Locked makes that protection irreversible. Vault immutability does not apply to operational backups of blobs, files or disks.

Potential impact

  • Deleted backups can leave no recovery point available after an outage or compromise.
  • Losing both the source data and its backups can delay recovery or cause permanent loss.

Remediation

  • Enable immutability with Unlocked and check its effect on retention policies and operating procedures.
  • Consider Locked after testing. The lock is irreversible, so also inspect the Terraform plan for any vault replacement.
  • Use soft delete, least-privilege access and restore tests alongside immutability. It does not by itself ensure that backups are created or can be restored successfully.

Examples

These examples compare immutability settings. Keep the existing vault name when changing its protection; changing the name creates a new vault.

Before

hcl
resource "azurerm_data_protection_backup_vault" "backup_vault" {
  name                = "app-backup-vault"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  datastore_type      = "VaultStore"
  redundancy          = "LocallyRedundant"
  immutability        = "Disabled"
}

Immutability is disabled. This setting does not block backup deletion that other permission controls allow.

After

hcl
resource "azurerm_data_protection_backup_vault" "backup_vault" {
  name                = "protected-backup-vault"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  datastore_type      = "VaultStore"
  redundancy          = "LocallyRedundant"
  immutability        = "Locked"
}

Immutability is locked and cannot be disabled. Confirm retention requirements and operational effects before applying it.

References