{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
        "slug": "dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/"
        },
        "title": "Replace ineffective diagnostic retention settings without overwriting other lifecycle rules",
        "summary": "Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:30+00:00",
        "modified_at": "2026-09-10T02:04:58+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 240,
        "potentially_affected": "Diagnostic settings that send logs to an Azure Storage account.",
        "dse_recommendation": "Inspect the storage account's complete lifecycle policy before recreating diagnostic-log retention there.",
        "primary_source": {
            "name": "Migrate from Diagnostic Settings Storage Retention to Azure Storage Lifecycle Management - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Diagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft&#8217;s replacement is an Azure Storage lifecycle management policy on the destination account. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft&#8217;s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account&#8217;s existing lifecycle policy rather than partially updating it. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source&#8217;s example retention period into production without an explicit local decision.</p>\n<h2>Verification</h2>\n<p>Compare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Migrate diagnostic storage retention</a>.</p>",
        "content_text": "Source facts\nDiagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft’s replacement is an Azure Storage lifecycle management policy on the destination account. Microsoft Learn.\nThe migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft’s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account’s existing lifecycle policy rather than partially updating it. Microsoft Learn.\nApplicability\nUse this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.\nDSE recommendation\nDSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source’s example retention period into production without an explicit local decision.\nVerification\nCompare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.\nOfficial references\nMicrosoft Learn: Migrate diagnostic storage retention.",
        "content_markdown": "## Source facts\n\nDiagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft’s replacement is an Azure Storage lifecycle management policy on the destination account. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy).\n\nThe migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft’s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account’s existing lifecycle policy rather than partially updating it. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy).\n\n## Applicability\n\nUse this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.\n\n## DSE recommendation\n\nDSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source’s example retention period into production without an explicit local decision.\n\n## Verification\n\nCompare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.\n\n## Official references\n\n[Microsoft Learn: Migrate diagnostic storage retention](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Replace ineffective diagnostic retention settings without overwriting other lifecycle rules",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/",
                "headline": "Replace ineffective diagnostic retention settings without overwriting other lifecycle rules",
                "description": "Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?",
                "abstract": "Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?",
                "articleBody": "Source facts\nDiagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft’s replacement is an Azure Storage lifecycle management policy on the destination account. Microsoft Learn.\nThe migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft’s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account’s existing lifecycle policy rather than partially updating it. Microsoft Learn.\nApplicability\nUse this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.\nDSE recommendation\nDSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source’s example retention period into production without an explicit local decision.\nVerification\nCompare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.\nOfficial references\nMicrosoft Learn: Migrate diagnostic storage retention.",
                "datePublished": "2026-09-10T00:24:30+00:00",
                "dateModified": "2026-09-10T02:04:58+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Replace ineffective diagnostic retention settings without overwriting other lifecycle rules"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 240,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Migrate from Diagnostic Settings Storage Retention to Azure Storage Lifecycle Management - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy"
                }
            }
        ]
    }
}