Review Azure Key Vault purge protection

Check Key Vault purge protection and the recovery retention period.

Description

Key Vault purge protection prevents soft-deleted secrets and keys from being permanently removed before their retention period ends. Without it, misuse of purge permissions can make recovery impossible.

Purge protection does not prevent the initial deletion or resulting service interruption. Manage permissions and recovery procedures so deleted items can be restored within the retention period.

Potential impact

  • Permanent loss of keys, secrets or certificates can interrupt dependent services.
  • Losing an encryption key can make encrypted data unrecoverable; simply creating a new key does not replace it.

Remediation

Set purge_protection_enabled = true. Once enabled, protection cannot be disabled, so review the impact first. The soft-delete retention period is between 7 and 90 days, is chosen at creation and cannot later be changed. Review deletion permissions, backups and recovery procedures within that period.

Examples

These excerpts compare purge protection on the same Key Vault.

Before

hcl
resource "azurerm_key_vault" "app_key_vault" {
  name                       = "examplekeyvault"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  tenant_id                  = data.azurerm_client_config.current.tenant_id
  sku_name                   = "standard"
  soft_delete_retention_days = 7
  purge_protection_enabled   = false
}

With purge protection disabled, an authorized identity can permanently remove a soft-deleted item before the retention period ends.

After

hcl
resource "azurerm_key_vault" "app_key_vault" {
  name                       = "examplekeyvault"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  tenant_id                  = data.azurerm_client_config.current.tenant_id
  sku_name                   = "standard"
  soft_delete_retention_days = 7
  purge_protection_enabled   = true
}

Purge protection prevents permanent deletion until the retention period expires. The example provides a seven-day recovery period, not indefinite retention.

References