Review Azure file share soft delete

Verify Azure file share soft delete and retention so an entire deleted share can be recovered.

Description

Azure Files soft delete keeps a deleted file share and its contents recoverable for a defined period. If protection is disabled or retention expires, deleting a share can cause service interruption or data loss.

This feature works at share level; it does not recover individual files deleted from an existing share. Use share snapshots or backups for those files. New storage accounts enable soft delete by default, but verify the actual account settings and retention.

Potential impact

  • Failure to recover a deleted share can mean losing all the data within it.
  • A missing mounted file path can interrupt applications and require restoration from backup.

Remediation

  • Configure share_properties.retention_policy and choose days according to operational importance and the time needed to discover deletion.
  • Test restoring a share within the retention period and review retention costs.
  • Maintain snapshots or backups for individual files, and restrict permissions to delete shares and storage accounts.

Examples

These examples show an explicit soft-delete retention policy. When applying it to an existing account, preserve its other attributes, including its name, and check the Terraform plan for replacement.

Before

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "filesharestore01"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  share_properties {
  }
}

No share retention policy is specified. Verify the effective soft-delete setting and retention rather than assuming a default.

After

hcl
resource "azurerm_storage_account" "storage_account" {
  name                     = "filesharestore02"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Standard"
  account_replication_type = "LRS"

  share_properties {
    retention_policy {
      days = 7
    }
  }
}

Deleted file shares remain recoverable for 7 days. Increase the period if your recovery requirements need more time.

References