Beta - Azure storage account deletion protection needs review

Review existing and inherited locks on an Azure storage account and apply deletion protection at the required scope.

Description

An Azure management lock helps prevent accidental deletion of a storage account, including deletion by users who otherwise have permission to delete it. In Terraform, an azurerm_management_lock with lock_level set to CanNotDelete can restrict deletion at a scope containing the azurerm_storage_account.

Locks can be inherited from a resource group or subscription, and ReadOnly locks also prevent deletion. Management locks apply to control-plane operations, so distinguish them from features that protect against data-plane deletion, such as deleting blob contents.

Potential impact

  • If deletion protection is actually absent, an authorized user could delete the account accidentally or deliberately.
  • Deleting the account can disrupt applications, log collection, and backup operations.
  • Misunderstanding the lock's scope can create a false expectation that the data inside the account is also protected.

Remediation

  • First inspect locks on the storage account and its parent resource group and subscription.
  • If deletion protection is needed and no lock applies, add a CanNotDelete management lock at the appropriate scope. Retain an intentional ReadOnly lock when its restrictions on changes are also required.
  • Review who can manage locks and how they are removed. Use separate recovery and access-control features to protect the data itself.

Examples

These excerpts compare the presence and absence of a lock. They omit fields such as resource_group_name that a complete Terraform configuration requires. Check for existing locks at parent scopes separately.

Before

hcl
resource "azurerm_storage_account" "example" {
  name                     = "examplestorageacct"
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "LRS"
}

After

hcl
resource "azurerm_storage_account" "example" {
  name                     = "examplestorageacct"
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "LRS"
}

resource "azurerm_management_lock" "storage_delete_lock" {
  name       = "storage-delete-lock"
  scope      = azurerm_storage_account.example.id
  lock_level = "CanNotDelete"
  notes      = "Prevent accidental deletion of the storage account"
}

Explanation:

  • Before: The excerpt defines no management lock for the storage account.
  • After: A CanNotDelete lock is added at account scope. It restricts control-plane deletion of the account, but does not guarantee protection against all data deletion or actions by users authorized to remove the lock.

References