Review Recovery Services Vault backup immutability

Protect Recovery Services Vault backups from deletion before retention expires.

Description

Recovery Services Vault immutability restricts deletion and retention reductions that would lose backups before their retention period ends. It helps preserve recovery points against ransomware or misuse of permissions.

Unlocked enables protection but allows it to be disabled; Locked makes it irreversible. Immutability protects supported vaulted backup data, not every resource setting or operational backup.

Potential impact

Premature backup deletion can prevent recovery to a state before an outage or compromise, increasing downtime and data loss.

Remediation

Enable immutability for supported vaulted backups according to retention requirements. Verify policies and restore operations in Unlocked mode, then assess the operational impact before moving to Locked. Retain soft delete and access controls alongside it.

Examples

These excerpts compare vault settings. When changing an existing vault, retain its actual name and inspect the Terraform replacement plan.

Before

hcl
resource "azurerm_recovery_services_vault" "recovery_vault" {
  name                = "app-recovery-vault"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  sku                 = "Standard"
  immutability        = "Disabled"
}

Backup immutability protection is disabled.

After

hcl
resource "azurerm_recovery_services_vault" "recovery_vault" {
  name                = "protected-recovery-vault"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  sku                 = "Standard"
  immutability        = "Locked"
}

Protection is enabled and locked. Moving to Locked is irreversible, so verify retention policies and operational requirements first.

References