What you need to know
A failed move to version-level immutability can leave blob policies that the portal does not yet display.
Potentially affected
Existing Azure Blob containers being migrated to version-level immutability support.
DSE recommendation
Inspect migration evidence and prerequisites before retrying; do not infer unchanged state from the portal alone.
Source facts
Microsoft warns that a failed migration can leave some blobs with version-level policies not yet visible in the portal. The displayed policy scope remains at container level until migration succeeds. The storage account Activity Log’s Write Migrate operation can establish the migration failure.
The migration requires account-level versioning and an existing container time-based policy. An active lease on the container or any contained blob blocks migration; an existing container-level legal hold is also a blocker. Microsoft describes container migration as irreversible. Microsoft Learn.
Applicability
Identify the exact container, migration operation and protection configuration. Review current account feature support before planning the migration; this is not advice to remove retention protections.
DSE recommendation
DSE recommends retaining the failed operation and inspecting prerequisites before another attempt. Investigate leases with their application owners. Escalate any hold-related blocker to the responsible records or legal authority rather than clearing it to make a technical task succeed. Do not promise rollback to the original configuration or treat an unchanged portal label as evidence that every blob is unchanged.
Verification
In an approved representative test, compare operation status, container scope and selected blob-version properties. Record unresolved inconsistencies and obtain support where state cannot be explained. Close the migration only after the successful result and intended protection state are verified together, without destructive probes against protected production data.
Official references
Microsoft Learn: Configure immutability policies for blob versions. Source retrieved September 9, 2026.
Review the official source
Configure immutability policies for blob versions - Azure Storage | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE