# Replace ineffective diagnostic retention settings without overwriting other lifecycle rules

> Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:30+00:00
- Modified: 2026-09-10T02:04:58+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?

## Potentially affected

Diagnostic settings that send logs to an Azure Storage account.

## DSE recommendation

Inspect the storage account's complete lifecycle policy before recreating diagnostic-log retention there.

## Article

## Source facts

Diagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft’s replacement is an Azure Storage lifecycle management policy on the destination account. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy).

The migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft’s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account’s existing lifecycle policy rather than partially updating it. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy).

## Applicability

Use this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.

## DSE recommendation

DSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source’s example retention period into production without an explicit local decision.

## Verification

Compare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.

## Official references

[Microsoft Learn: Migrate diagnostic storage retention](https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy).

## Primary reference

- Name: Migrate from Diagnostic Settings Storage Retention to Azure Storage Lifecycle Management - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/platform/migrate-to-azure-storage-lifecycle-policy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Replace ineffective diagnostic retention settings without overwriting other lifecycle rules,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-446-replace-ineffective-diagnostic-retention-settings-without-overwriting-other/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
