{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/azure-backup-soft-delete-recovery-exercise/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
        "slug": "azure-backup-soft-delete-recovery-exercise",
        "url": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/azure-backup-soft-delete-recovery-exercise/"
        },
        "title": "Exercise Azure Backup soft-delete recovery before the retention clock expires",
        "summary": "Azure Backup soft delete delays permanent deletion for a configured retention period, but workload and vault support, regional state, recovery-point limits, and restore procedure still require verification.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "video-evidence",
            "label": "Video evidence & analytics",
            "alt": "Multiple synchronized camera views converging into a verifiable evidence frame.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/video-evidence-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/video-evidence-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/video-evidence-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:34:57+00:00",
        "modified_at": "2026-08-25T21:43:55+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 469,
        "potentially_affected": "Azure Recovery Services vaults and Backup vaults protecting supported Azure and hybrid workloads.",
        "dse_recommendation": "Confirm soft-delete state and retention per vault, alert on deletion, exercise undelete and restore for each critical workload, and add immutability or multiuser authorization where risk requires.",
        "primary_source": {
            "name": "Secure by default with soft delete for Azure Backup",
            "url": "https://learn.microsoft.com/en-us/azure/backup/secure-by-default",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> Azure Backup soft delete keeps supported deleted backup data recoverable for a configured period instead of immediately destroying it. Microsoft documents a default retention period and optional extension, with service, vault, workload, region, API, and availability-status differences. Recovery still has to be detected, authorized, performed, and validated before time expires.</p>\n<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft&#8217;s <a href=\"https://learn.microsoft.com/en-us/azure/backup/secure-by-default\" target=\"_blank\" rel=\"noopener noreferrer\">secure-by-default soft-delete documentation</a> says deleted backup items and supported vault data remain in a soft-deleted state during the retention period. The documented default is 14 days, and the period can be extended within stated limits, with pricing implications beyond the included period.</p>\n<p>The page distinguishes Recovery Services vault and Backup vault availability by region and general-availability or preview state. It lists workload boundaries, including differences for vaulted data, operational backups, snapshots, and log recovery points for specified database workloads. Microsoft documents recovery, resume-protection, vault deletion, API and tool-version behavior, and the effect of the retention value active at the time of deletion. Secure-by-default enforcement does not have identical status for every vault and region.</p>\n<h2>What the source does not establish</h2>\n<p>Soft delete does not prove that backups are current, uncompromised, application-consistent, immutable, or restorable. It does not stop a destructive actor from waiting out the retention period, attacking source and recovery credentials, or changing future backup policy. A recovered backup item is not the same as a validated application recovery. Preview capability should not be represented as universal general availability.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Is each protected item in a Recovery Services vault or Backup vault, and in which region and availability state?</li>\n<li>Is the workload vaulted or operational, and which soft-delete and recovery-point limitations apply?</li>\n<li>How long could malicious deletion remain undetected, and does retention exceed that period?</li>\n<li>Who can stop protection, delete, recover, change retention, or alter vault security features?</li>\n<li>Are immutability, multiuser authorization, protected alerts, and independent administrative accounts required?</li>\n</ul>\n<h2>DSE recommendation: controlled next steps</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Inventory vault type, region, workload, soft-delete state, retention, API or tool paths, and documented support.</li>\n<li>Set retention from realistic detection and response time, with cost review for extended periods.</li>\n<li>Alert on stop-protection, delete, retention reduction, vault change, and recovery operations through protected channels.</li>\n<li>Exercise deletion, undelete, restore, and resume protection for each critical workload in a safe scope. Validate the restored application or data.</li>\n<li>Add immutability, multiuser authorization, identity separation, and independent recovery documentation according to threat and continuity requirements.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<ul>\n<li>Preserve vault configuration, security features, retention, workload support, roles, alerts, and approval.</li>\n<li>Record deletion and recovery timestamps, recovery points, commands or portal actions, and observed state transitions.</li>\n<li>Validate restored data and application function outside the original failure path.</li>\n<li>Demonstrate alerts reach responders with enough time to act before retention expires.</li>\n</ul>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/azure/backup/secure-by-default\" target=\"_blank\" rel=\"noopener noreferrer\">Secure by default with soft delete for Azure Backup</a> — Microsoft</li>\n</ul>",
        "content_text": "Bottom line: Azure Backup soft delete keeps supported deleted backup data recoverable for a configured period instead of immediately destroying it. Microsoft documents a default retention period and optional extension, with service, vault, workload, region, API, and availability-status differences. Recovery still has to be detected, authorized, performed, and validated before time expires.\nSource fact: what Microsoft documents\nMicrosoft’s secure-by-default soft-delete documentation says deleted backup items and supported vault data remain in a soft-deleted state during the retention period. The documented default is 14 days, and the period can be extended within stated limits, with pricing implications beyond the included period.\nThe page distinguishes Recovery Services vault and Backup vault availability by region and general-availability or preview state. It lists workload boundaries, including differences for vaulted data, operational backups, snapshots, and log recovery points for specified database workloads. Microsoft documents recovery, resume-protection, vault deletion, API and tool-version behavior, and the effect of the retention value active at the time of deletion. Secure-by-default enforcement does not have identical status for every vault and region.\nWhat the source does not establish\nSoft delete does not prove that backups are current, uncompromised, application-consistent, immutable, or restorable. It does not stop a destructive actor from waiting out the retention period, attacking source and recovery credentials, or changing future backup policy. A recovered backup item is not the same as a validated application recovery. Preview capability should not be represented as universal general availability.\nApplicability questions\n\nIs each protected item in a Recovery Services vault or Backup vault, and in which region and availability state?\nIs the workload vaulted or operational, and which soft-delete and recovery-point limitations apply?\nHow long could malicious deletion remain undetected, and does retention exceed that period?\nWho can stop protection, delete, recover, change retention, or alter vault security features?\nAre immutability, multiuser authorization, protected alerts, and independent administrative accounts required?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nInventory vault type, region, workload, soft-delete state, retention, API or tool paths, and documented support.\nSet retention from realistic detection and response time, with cost review for extended periods.\nAlert on stop-protection, delete, retention reduction, vault change, and recovery operations through protected channels.\nExercise deletion, undelete, restore, and resume protection for each critical workload in a safe scope. Validate the restored application or data.\nAdd immutability, multiuser authorization, identity separation, and independent recovery documentation according to threat and continuity requirements.\n\nVerification and evidence\n\nPreserve vault configuration, security features, retention, workload support, roles, alerts, and approval.\nRecord deletion and recovery timestamps, recovery points, commands or portal actions, and observed state transitions.\nValidate restored data and application function outside the original failure path.\nDemonstrate alerts reach responders with enough time to act before retention expires.\n\nOfficial references\n\nSecure by default with soft delete for Azure Backup — Microsoft",
        "content_markdown": "Bottom line: Azure Backup soft delete keeps supported deleted backup data recoverable for a configured period instead of immediately destroying it. Microsoft documents a default retention period and optional extension, with service, vault, workload, region, API, and availability-status differences. Recovery still has to be detected, authorized, performed, and validated before time expires.\n\n## Source fact: what Microsoft documents\n\nMicrosoft’s [secure-by-default soft-delete documentation](https://learn.microsoft.com/en-us/azure/backup/secure-by-default) says deleted backup items and supported vault data remain in a soft-deleted state during the retention period. The documented default is 14 days, and the period can be extended within stated limits, with pricing implications beyond the included period.\n\nThe page distinguishes Recovery Services vault and Backup vault availability by region and general-availability or preview state. It lists workload boundaries, including differences for vaulted data, operational backups, snapshots, and log recovery points for specified database workloads. Microsoft documents recovery, resume-protection, vault deletion, API and tool-version behavior, and the effect of the retention value active at the time of deletion. Secure-by-default enforcement does not have identical status for every vault and region.\n\n## What the source does not establish\n\nSoft delete does not prove that backups are current, uncompromised, application-consistent, immutable, or restorable. It does not stop a destructive actor from waiting out the retention period, attacking source and recovery credentials, or changing future backup policy. A recovered backup item is not the same as a validated application recovery. Preview capability should not be represented as universal general availability.\n\n## Applicability questions\n\n- Is each protected item in a Recovery Services vault or Backup vault, and in which region and availability state?\n\n- Is the workload vaulted or operational, and which soft-delete and recovery-point limitations apply?\n\n- How long could malicious deletion remain undetected, and does retention exceed that period?\n\n- Who can stop protection, delete, recover, change retention, or alter vault security features?\n\n- Are immutability, multiuser authorization, protected alerts, and independent administrative accounts required?\n\n## DSE recommendation: controlled next steps\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Inventory vault type, region, workload, soft-delete state, retention, API or tool paths, and documented support.\n\n- Set retention from realistic detection and response time, with cost review for extended periods.\n\n- Alert on stop-protection, delete, retention reduction, vault change, and recovery operations through protected channels.\n\n- Exercise deletion, undelete, restore, and resume protection for each critical workload in a safe scope. Validate the restored application or data.\n\n- Add immutability, multiuser authorization, identity separation, and independent recovery documentation according to threat and continuity requirements.\n\n## Verification and evidence\n\n- Preserve vault configuration, security features, retention, workload support, roles, alerts, and approval.\n\n- Record deletion and recovery timestamps, recovery points, commands or portal actions, and observed state transitions.\n\n- Validate restored data and application function outside the original failure path.\n\n- Demonstrate alerts reach responders with enough time to act before retention expires.\n\n## Official references\n\n- [Secure by default with soft delete for Azure Backup](https://learn.microsoft.com/en-us/azure/backup/secure-by-default) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
                "url": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Exercise Azure Backup soft-delete recovery before the retention clock expires",
                        "item": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/#article",
                "identifier": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
                "url": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/",
                "headline": "Exercise Azure Backup soft-delete recovery before the retention clock expires",
                "description": "Azure Backup soft delete delays permanent deletion for a configured retention period, but workload and vault support, regional state, recovery-point…",
                "abstract": "Azure Backup soft delete delays permanent deletion for a configured retention period, but workload and vault support, regional state, recovery-point limits, and restore procedure still require verification.",
                "articleBody": "Bottom line: Azure Backup soft delete keeps supported deleted backup data recoverable for a configured period instead of immediately destroying it. Microsoft documents a default retention period and optional extension, with service, vault, workload, region, API, and availability-status differences. Recovery still has to be detected, authorized, performed, and validated before time expires.\nSource fact: what Microsoft documents\nMicrosoft’s secure-by-default soft-delete documentation says deleted backup items and supported vault data remain in a soft-deleted state during the retention period. The documented default is 14 days, and the period can be extended within stated limits, with pricing implications beyond the included period.\nThe page distinguishes Recovery Services vault and Backup vault availability by region and general-availability or preview state. It lists workload boundaries, including differences for vaulted data, operational backups, snapshots, and log recovery points for specified database workloads. Microsoft documents recovery, resume-protection, vault deletion, API and tool-version behavior, and the effect of the retention value active at the time of deletion. Secure-by-default enforcement does not have identical status for every vault and region.\nWhat the source does not establish\nSoft delete does not prove that backups are current, uncompromised, application-consistent, immutable, or restorable. It does not stop a destructive actor from waiting out the retention period, attacking source and recovery credentials, or changing future backup policy. A recovered backup item is not the same as a validated application recovery. Preview capability should not be represented as universal general availability.\nApplicability questions\n\nIs each protected item in a Recovery Services vault or Backup vault, and in which region and availability state?\nIs the workload vaulted or operational, and which soft-delete and recovery-point limitations apply?\nHow long could malicious deletion remain undetected, and does retention exceed that period?\nWho can stop protection, delete, recover, change retention, or alter vault security features?\nAre immutability, multiuser authorization, protected alerts, and independent administrative accounts required?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nInventory vault type, region, workload, soft-delete state, retention, API or tool paths, and documented support.\nSet retention from realistic detection and response time, with cost review for extended periods.\nAlert on stop-protection, delete, retention reduction, vault change, and recovery operations through protected channels.\nExercise deletion, undelete, restore, and resume protection for each critical workload in a safe scope. Validate the restored application or data.\nAdd immutability, multiuser authorization, identity separation, and independent recovery documentation according to threat and continuity requirements.\n\nVerification and evidence\n\nPreserve vault configuration, security features, retention, workload support, roles, alerts, and approval.\nRecord deletion and recovery timestamps, recovery points, commands or portal actions, and observed state transitions.\nValidate restored data and application function outside the original failure path.\nDemonstrate alerts reach responders with enough time to act before retention expires.\n\nOfficial references\n\nSecure by default with soft delete for Azure Backup — Microsoft",
                "datePublished": "2026-08-25T21:34:57+00:00",
                "dateModified": "2026-08-25T21:43:55+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/azure-backup-soft-delete-recovery-exercise/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/video-evidence-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/video-evidence-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Exercise Azure Backup soft-delete recovery before the retention clock expires"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 469,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Secure by default with soft delete for Azure Backup",
                    "url": "https://learn.microsoft.com/en-us/azure/backup/secure-by-default"
                }
            }
        ]
    }
}