Exercise Azure Backup soft-delete recovery before the retention clock expires

Azure Backup soft delete delays permanent deletion for a configured retention period, but workload and vault support, regional state, recovery-point limits, and restore procedure still require verification.

Multiple synchronized camera views converging into a verifiable evidence frame.
DSE visual intelligenceVideo evidence & analyticsPlaybook · 3 min read
Executive summary

What you need to know

Azure Backup soft delete delays permanent deletion for a configured retention period, but workload and vault support, regional state, recovery-point limits, and restore procedure still require verification.

Potentially affected

Azure Recovery Services vaults and Backup vaults protecting supported Azure and hybrid workloads.

DSE recommendation

Confirm soft-delete state and retention per vault, alert on deletion, exercise undelete and restore for each critical workload, and add immutability or multiuser authorization where risk requires.

Bottom line: Azure Backup soft delete keeps supported deleted backup data recoverable for a configured period instead of immediately destroying it. Microsoft documents a default retention period and optional extension, with service, vault, workload, region, API, and availability-status differences. Recovery still has to be detected, authorized, performed, and validated before time expires.

Source fact: what Microsoft documents

Microsoft’s secure-by-default soft-delete documentation says deleted backup items and supported vault data remain in a soft-deleted state during the retention period. The documented default is 14 days, and the period can be extended within stated limits, with pricing implications beyond the included period.

The page distinguishes Recovery Services vault and Backup vault availability by region and general-availability or preview state. It lists workload boundaries, including differences for vaulted data, operational backups, snapshots, and log recovery points for specified database workloads. Microsoft documents recovery, resume-protection, vault deletion, API and tool-version behavior, and the effect of the retention value active at the time of deletion. Secure-by-default enforcement does not have identical status for every vault and region.

What the source does not establish

Soft delete does not prove that backups are current, uncompromised, application-consistent, immutable, or restorable. It does not stop a destructive actor from waiting out the retention period, attacking source and recovery credentials, or changing future backup policy. A recovered backup item is not the same as a validated application recovery. Preview capability should not be represented as universal general availability.

Applicability questions

  • Is each protected item in a Recovery Services vault or Backup vault, and in which region and availability state?
  • Is the workload vaulted or operational, and which soft-delete and recovery-point limitations apply?
  • How long could malicious deletion remain undetected, and does retention exceed that period?
  • Who can stop protection, delete, recover, change retention, or alter vault security features?
  • Are immutability, multiuser authorization, protected alerts, and independent administrative accounts required?

DSE recommendation: controlled next steps

The following steps are DSE recommendations based on the cited source.

  1. Inventory vault type, region, workload, soft-delete state, retention, API or tool paths, and documented support.
  2. Set retention from realistic detection and response time, with cost review for extended periods.
  3. Alert on stop-protection, delete, retention reduction, vault change, and recovery operations through protected channels.
  4. Exercise deletion, undelete, restore, and resume protection for each critical workload in a safe scope. Validate the restored application or data.
  5. Add immutability, multiuser authorization, identity separation, and independent recovery documentation according to threat and continuity requirements.

Verification and evidence

  • Preserve vault configuration, security features, retention, workload support, roles, alerts, and approval.
  • Record deletion and recovery timestamps, recovery points, commands or portal actions, and observed state transitions.
  • Validate restored data and application function outside the original failure path.
  • Demonstrate alerts reach responders with enough time to act before retention expires.

Official references

Primary reference

Review the official source

Secure by default with soft delete for Azure Backup · Verified August 25, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE