Description
An Azure management lock helps prevent accidental deletion of a storage account, including deletion by users who otherwise have permission to delete it. In Terraform, an azurerm_management_lock with lock_level set to CanNotDelete can restrict deletion at a scope containing the azurerm_storage_account.
Locks can be inherited from a resource group or subscription, and ReadOnly locks also prevent deletion. Management locks apply to control-plane operations, so distinguish them from features that protect against data-plane deletion, such as deleting blob contents.
Potential impact
- If deletion protection is actually absent, an authorized user could delete the account accidentally or deliberately.
- Deleting the account can disrupt applications, log collection, and backup operations.
- Misunderstanding the lock's scope can create a false expectation that the data inside the account is also protected.
Remediation
- First inspect locks on the storage account and its parent resource group and subscription.
- If deletion protection is needed and no lock applies, add a
CanNotDeletemanagement lock at the appropriate scope. Retain an intentionalReadOnlylock when its restrictions on changes are also required. - Review who can manage locks and how they are removed. Use separate recovery and access-control features to protect the data itself.
Examples
These excerpts compare the presence and absence of a lock. They omit fields such as resource_group_name that a complete Terraform configuration requires. Check for existing locks at parent scopes separately.
Before
resource "azurerm_storage_account" "example" {
name = "examplestorageacct"
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
}
After
resource "azurerm_storage_account" "example" {
name = "examplestorageacct"
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "LRS"
}
resource "azurerm_management_lock" "storage_delete_lock" {
name = "storage-delete-lock"
scope = azurerm_storage_account.example.id
lock_level = "CanNotDelete"
notes = "Prevent accidental deletion of the storage account"
}
Explanation:
- Before: The excerpt defines no management lock for the storage account.
- After: A
CanNotDeletelock is added at account scope. It restricts control-plane deletion of the account, but does not guarantee protection against all data deletion or actions by users authorized to remove the lock.