Description
Recovery Services Vault immutability restricts deletion and retention reductions that would lose backups before their retention period ends. It helps preserve recovery points against ransomware or misuse of permissions.
Unlocked enables protection but allows it to be disabled; Locked makes it irreversible. Immutability protects supported vaulted backup data, not every resource setting or operational backup.
Potential impact
Premature backup deletion can prevent recovery to a state before an outage or compromise, increasing downtime and data loss.
Remediation
Enable immutability for supported vaulted backups according to retention requirements. Verify policies and restore operations in Unlocked mode, then assess the operational impact before moving to Locked. Retain soft delete and access controls alongside it.
Examples
These excerpts compare vault settings. When changing an existing vault, retain its actual name and inspect the Terraform replacement plan.
Before
resource "azurerm_recovery_services_vault" "recovery_vault" {
name = "app-recovery-vault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
sku = "Standard"
immutability = "Disabled"
}
Backup immutability protection is disabled.
After
resource "azurerm_recovery_services_vault" "recovery_vault" {
name = "protected-recovery-vault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
sku = "Standard"
immutability = "Locked"
}
Protection is enabled and locked. Moving to Locked is irreversible, so verify retention policies and operational requirements first.