Description
Soft delete retains deleted backup data for a period, providing an opportunity to recover after accidental or malicious deletion. An insufficient recovery window or a delayed response can still result in lost recovery points.
Azure now enforces soft delete for Recovery Services vaults. A legacy soft_delete_enabled = false configuration therefore does not establish that protection is actually disabled. Check the vault’s effective state and retention period.
Potential impact
Failure to recover deleted backups in time can remove recovery points needed during an incident, increasing downtime and data loss.
Remediation
Specify soft_delete_enabled = true in Terraform and verify the vault’s actual deletion protection and retention period. Prepare alerts and restore procedures that allow incidents to be discovered and addressed within that period. Manage immutability, backup policies and deletion permissions as well.
Examples
These excerpts compare soft-delete settings. When modifying an existing vault, retain its actual name and review any replacement.
Before
resource "azurerm_recovery_services_vault" "recovery_vault" {
name = "app-recovery-vault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
sku = "Standard"
soft_delete_enabled = false
}
This legacy configuration requests disabling protection. The service enforces soft delete, so this value does not guarantee effective disablement.
After
resource "azurerm_recovery_services_vault" "recovery_vault" {
name = "protected-recovery-vault"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
sku = "Standard"
soft_delete_enabled = true
}
The configuration explicitly enables recovery protection after deletion. Verify the applied retention period and recovery procedures.