# End active disk-restore-point access before an approved restore-point deletion

> Why can an Azure restore point resist deletion even after its retention review approves removal?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-078-end-active-disk-restore-point-access-before-an-approved-restore-point-deletion/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:38+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Why can an Azure restore point resist deletion even after its retention review approves removal?

## Potentially affected

Operators investigating DiskRestorePointUsedByCustomer while deleting an Azure VM restore point.

## DSE recommendation

Identify and coordinate the outstanding disk access before ending it and retrying the authorized deletion.

## Article

## Source facts

Azure blocks deletion of a restore point while any underlying disk restore point has an active shared access signature. Microsoft identifies this condition with DiskRestorePointUsedByCustomer and directs the operator to call EndGetAccess before deletion. The documented resolution ends shared access on the disk restore points and then retries the operation. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/restore-point-troubleshooting).

## Applicability

Use this check for the specific active-access error, not every restore-point failure. Confirm that retention and recovery owners have already approved deletion of the exact restore point. Identify whether an export, investigation, or recovery process still depends on the access being granted.

## DSE recommendation

Identify and coordinate the outstanding disk access before ending it and retrying the authorized deletion. Ask the access owner whether the consuming operation has finished and preserve its outcome. Keep resource identifiers and approval evidence in the ticket, but exclude the SAS URL itself. Do not respond to this error by broadening administrative permissions or deleting unrelated recovery material.

## Verification

After the approved access-ending operation, retry deletion only for the selected restore point and inspect its result. Reconcile the final restore-point inventory with the retention decision and confirm that no unrelated item changed. If deletion still fails, preserve the new error and investigate its stated cause rather than repeatedly ending access across the collection. Close the cleanup record only when both the consumer handoff and the intended resource disposition are accounted for.

## Official references

[Microsoft Learn: Troubleshoot restore point failures](https://learn.microsoft.com/en-us/azure/virtual-machines/restore-point-troubleshooting). Source reviewed September 9, 2026.

## Primary reference

- Name: Troubleshoot restore point failures - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/restore-point-troubleshooting
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “End active disk-restore-point access before an approved restore-point deletion,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-078-end-active-disk-restore-point-access-before-an-approved-restore-point-deletion/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
