# Approve attached-resource delete policies before retiring an Azure VM

> Which Azure disks and network resources should survive when a VM is deleted?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-045-approve-attached-resource-delete-policies-before-retiring-an-azure-vm/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:11+00:00
- Modified: 2026-09-10T00:32:01+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which Azure disks and network resources should survive when a VM is deleted?

## Potentially affected

Operators retiring Azure VMs with attached managed disks, network interfaces, or public IP resources.

## DSE recommendation

Approve a resource-by-resource survival list and compare it with the VM's actual delete options before deletion.

## Article

## Source facts

For managed disks and NICs, Azure’s Delete option permanently removes the associated resource when the VM is deleted; Detach leaves that resource available for reuse. Microsoft documents configurable behavior for managed disks, NICs, and public IPs. The public IP’s Delete behavior is linked to deletion of its associated NIC. Shared disks cannot use Delete as their deleteOption. The documentation also warns against force deletion when virtual hard disks are intended for reuse. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/delete).

## Applicability

Identify the exact VM and every attached resource before approving retirement. Distinguish resources that must be retained for investigation, replacement, or recovery from those approved for removal. Inspect the actual options rather than inferring them from the creation tool or a different VM’s defaults.

## DSE recommendation

Approve a resource-by-resource survival list and compare it with the VM’s actual delete options before deletion. Have the data and network owners review their respective entries, including any shared disk and whether the NIC itself will be retained. Resolve a disagreement between the intended outcome and configured behavior before proceeding. Keep replacement planning separate from expedited cleanup, and do not select force deletion merely to shorten a task that depends on disk reuse.

## Verification

Use a disposable representative VM to validate the approved policy pattern first. After an authorized retirement, reconcile every previously attached resource against its intended retained or removed state. Record the identifiers of retained disks and interfaces and assign their next owner or disposition. Investigate an unexpected survivor or missing resource explicitly; deletion of the VM object alone is not the completion criterion for the retirement record.

## Official references

[Microsoft Learn: Delete a VM and attached resources](https://learn.microsoft.com/en-us/azure/virtual-machines/delete). Source reviewed September 9, 2026.

## Primary reference

- Name: Delete a VM and attached resources - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/delete
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Approve attached-resource delete policies before retiring an Azure VM,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-045-approve-attached-resource-delete-policies-before-retiring-an-azure-vm/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
