Keep blob soft delete enabled after activating built-in malware remediation

What happens if blob soft delete is later disabled on an account using Defender's malicious-blob remediation?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

What happens if blob soft delete is later disabled on an account using Defender's malicious-blob remediation?

Potentially affected

Storage accounts using Defender for Storage's built-in soft delete malicious blobs capability.

DSE recommendation

Treat the storage account's soft-delete setting as a continuing remediation dependency, not only an installation prerequisite.

Source facts

Defender for Storage’s built-in malicious-blob remediation is disabled by default. When enabled, it can activate blob soft delete if necessary. Malicious blobs are soft deleted after on-upload or on-demand detection and remain recoverable in the same container during retention. If an administrator later disables the account’s soft-delete property, malicious blobs are not deleted: Defender raises an alert but does not enable the property again. Deletion failures can also reflect permissions or configuration problems. Microsoft Learn.

Applicability

Use this check for the built-in malicious-blob feature, not a separately authored move/delete workflow. Record the storage account, effective feature setting, blob soft-delete property and retention decision. Review versioning-specific restoration guidance where versioning is enabled. Detection and successful remediation should remain separate evidence items.

DSE recommendation

Treat the storage account’s soft-delete setting as a continuing remediation dependency, not only an installation prerequisite. Have the storage owner include it in change review and the response owner monitor remediation failures. Require an explicit security decision before turning it off. Establish who can investigate or restore a retained malicious blob, and keep any restoration isolated from normal application consumption until its purpose is approved.

Verification

In an authorized test account, inspect both feature configuration and the resulting disposition of a safe malware-test artifact. Confirm the alert handling for a failed deletion without introducing a production gap. Record whether the test blob was actually soft deleted and how its retained copy is controlled. Do not close the check merely because scanning produced a malicious verdict.

Official references

Microsoft Learn: Set up automated remediation for malware detection. Source reviewed September 9, 2026.

Primary reference

Review the official source

Set Up Automated Remediation for Malware Detection - Microsoft Defender for Cloud | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE