Review Azure Blob container soft-delete retention

Configure Azure Blob container soft delete and sufficient retention to recover from deletion of an entire container.

Description

Container soft delete retains a deleted container and its contents for recovery during a defined period. A single container deletion can affect many blobs, making separate recovery protection important.

This feature restores whole containers. Recovering individual blobs deleted from a container that still exists requires blob soft delete or versioning. Deletion of the storage account itself also needs separate protection.

Potential impact

  • Missing the recovery window for a deleted container can mean losing many blobs together.
  • Depending on backup restoration of large data sets can increase costs and delay service recovery.

Remediation

  • Set days in blob_properties.container_delete_retention_policy based on the time needed to discover and respond to deletion.
  • Review retention costs and test actual container recovery. Creating another container with the original name can prevent restoration.
  • Also configure blob soft delete and any required versioning or backups, and restrict deletion permissions.

Examples

These examples compare container retention of 5 and 49 days. Five days provides a recovery window, but Microsoft recommends at least 7 days and longer where operations require it. Keep other account attributes unchanged when modifying an existing account and inspect the Terraform plan.

Before

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "appcontainerstore"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  blob_properties {
    container_delete_retention_policy {
      days = 5
    }
  }
}

The container can be recovered for 5 days after deletion. A shorter period than your detection and response needs can eliminate the recovery opportunity.

After

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "protectedstore01"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Premium"
  account_replication_type = "LRS"

  blob_properties {
    container_delete_retention_policy {
      days = 49
    }
  }
}

The container recovery window is extended to 49 days. Adjust it according to data importance and retention costs.

References