Review Azure Backup Vault soft delete

Verify soft delete and retention in Azure Backup Vault so accidental or malicious deletion leaves time to recover backups.

Description

Soft delete retains deleted backup data for a defined period so it can be recovered. If this protection is actually disabled, an accidental or malicious deletion can cause permanent loss.

Azure is expanding enforcement of soft delete as a secure default. Disabling it may be prohibited depending on the Region and API version, so verify the actual vault protection as well as the Terraform setting.

Potential impact

  • Losing deleted backups can remove the recovery points needed after an outage or compromise.
  • Detecting deletion too late or exceeding the retention period can eliminate the opportunity to recover.

Remediation

  • Check the soft_delete options supported by your provider and use On or AlwaysOn. These are the spellings used by AzureRM 4.50.0.
  • AlwaysOn cannot later be disabled. Review retention and costs before applying it, and test whether deletion can be discovered and data restored within the retention period.
  • Combine soft delete with immutability, least privilege and deletion alerts. Do not bypass soft delete enforced by the service.

Examples

These examples use AzureRM 4.50.0 setting names. An Off request may be rejected where the service enforces soft delete. Keep an existing vault name unchanged and check the replacement plan when modifying it.

Before

hcl
resource "azurerm_data_protection_backup_vault" "backup_vault" {
  name                = "app-backup-vault"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  datastore_type      = "VaultStore"
  redundancy          = "LocallyRedundant"
  soft_delete         = "Off"
}

This requests that soft delete be disabled. The recovery protection after deletion depends on whether that request takes effect in the environment.

After

hcl
resource "azurerm_data_protection_backup_vault" "backup_vault" {
  name                = "protected-backup-vault"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  datastore_type      = "VaultStore"
  redundancy          = "LocallyRedundant"
  soft_delete         = "AlwaysOn"
}

This requests irreversible AlwaysOn protection. Also verify the actual retention period and the procedure for restoring deleted backups.

References