Review Azure Blob soft-delete retention

Configure Azure Blob soft delete and retention to allow time to discover deletion and recover data.

Description

Blob soft delete keeps deleted blobs, snapshots or versions recoverable for a defined period. Recovery becomes harder when protection is disabled or retention expires before deletion is discovered.

blob_properties.delete_retention_policy protects individual blobs. Deletion of an entire container or storage account requires separate protection.

Potential impact

  • Data deleted accidentally or through misuse may no longer be recoverable.
  • Depending on backup restoration or re-upload after a short retention period can delay service recovery.

Remediation

  • Configure blob_properties.delete_retention_policy and choose days based on the time needed to discover and recover from deletion.
  • Consider storage costs during retention alongside data importance, and test actual restoration.
  • Review container soft delete, any required versioning and backups, and restrict permissions to delete the storage account.

Examples

These examples compare retention of 5 and 49 days. Both configure soft delete; the necessary duration depends on operational needs. When updating an actual account, retain its other attributes, including name, location and tier, and inspect the Terraform plan.

Before

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "appstorage001"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  blob_properties {
    delete_retention_policy {
      days = 5
    }
  }
}

Deleted data remains recoverable for 5 days. This may be insufficient if discovering and responding to an incident takes longer.

After

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "protectedstore01"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Premium"
  account_replication_type = "LRS"

  blob_properties {
    delete_retention_policy {
      days = 49
    }
  }
}

The recovery window is extended to 49 days. This is not a universal requirement; choose a period that meets your recovery objectives.

References