Description
Blob soft delete keeps deleted blobs, snapshots or versions recoverable for a defined period. Recovery becomes harder when protection is disabled or retention expires before deletion is discovered.
blob_properties.delete_retention_policy protects individual blobs. Deletion of an entire container or storage account requires separate protection.
Potential impact
- Data deleted accidentally or through misuse may no longer be recoverable.
- Depending on backup restoration or re-upload after a short retention period can delay service recovery.
Remediation
- Configure
blob_properties.delete_retention_policyand choosedaysbased on the time needed to discover and recover from deletion. - Consider storage costs during retention alongside data importance, and test actual restoration.
- Review container soft delete, any required versioning and backups, and restrict permissions to delete the storage account.
Examples
These examples compare retention of 5 and 49 days. Both configure soft delete; the necessary duration depends on operational needs. When updating an actual account, retain its other attributes, including name, location and tier, and inspect the Terraform plan.
Before
resource "azurerm_storage_account" "storage_account" {
name = "appstorage001"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
blob_properties {
delete_retention_policy {
days = 5
}
}
}
Deleted data remains recoverable for 5 days. This may be insufficient if discovering and responding to an incident takes longer.
After
resource "azurerm_storage_account" "storage_account" {
name = "protectedstore01"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Premium"
account_replication_type = "LRS"
blob_properties {
delete_retention_policy {
days = 49
}
}
}
The recovery window is extended to 49 days. This is not a universal requirement; choose a period that meets your recovery objectives.