Description
Key Vault purge protection prevents soft-deleted secrets and keys from being permanently removed before their retention period ends. Without it, misuse of purge permissions can make recovery impossible.
Purge protection does not prevent the initial deletion or resulting service interruption. Manage permissions and recovery procedures so deleted items can be restored within the retention period.
Potential impact
- Permanent loss of keys, secrets or certificates can interrupt dependent services.
- Losing an encryption key can make encrypted data unrecoverable; simply creating a new key does not replace it.
Remediation
Set purge_protection_enabled = true. Once enabled, protection cannot be disabled, so review the impact first. The soft-delete retention period is between 7 and 90 days, is chosen at creation and cannot later be changed. Review deletion permissions, backups and recovery procedures within that period.
Examples
These excerpts compare purge protection on the same Key Vault.
Before
resource "azurerm_key_vault" "app_key_vault" {
name = "examplekeyvault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
tenant_id = data.azurerm_client_config.current.tenant_id
sku_name = "standard"
soft_delete_retention_days = 7
purge_protection_enabled = false
}
With purge protection disabled, an authorized identity can permanently remove a soft-deleted item before the retention period ends.
After
resource "azurerm_key_vault" "app_key_vault" {
name = "examplekeyvault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
tenant_id = data.azurerm_client_config.current.tenant_id
sku_name = "standard"
soft_delete_retention_days = 7
purge_protection_enabled = true
}
Purge protection prevents permanent deletion until the retention period expires. The example provides a seven-day recovery period, not indefinite retention.