GuideInformationBusiness ContinuityIT

Replace ineffective diagnostic retention settings without overwriting other lifecycle rules

Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 2 min read
Executive summary

What you need to know

Where should diagnostic-log retention be enforced after the old storage-retention feature stopped applying?

Potentially affected

Diagnostic settings that send logs to an Azure Storage account.

DSE recommendation

Inspect the storage account's complete lifecycle policy before recreating diagnostic-log retention there.

Source facts

Diagnostic-settings storage retention stopped operating across environments on September 30, 2025. A retention value still present on a diagnostic setting therefore does not enforce retention. Microsoft’s replacement is an Azure Storage lifecycle management policy on the destination account. Microsoft Learn.

The migration requires an existing storage destination and Storage Account Contributor, or equivalent managementPolicies permissions. Microsoft’s sample targets diagnostic blobs through a prefix filter. Its template warning is important: deployment replaces the account’s existing lifecycle policy rather than partially updating it. Microsoft Learn.

Applicability

Use this review for diagnostic settings that send logs to an Azure Storage account. The question is which active storage policy now enforces the intended retention, not whether the retired setting displays a plausible number.

DSE recommendation

DSE recommends exporting the current lifecycle policy and identifying the exact diagnostic containers and prefixes before preparing a replacement. Preserve unrelated rules in the proposed complete policy. Ask the evidence owner to approve the intended deletion age and scope. Do not copy the source’s example retention period into production without an explicit local decision.

Verification

Compare the complete deployed policy with the approved version, including unrelated rules, prefix filters and age conditions. Check representative diagnostic objects against that scope before accepting the migration. Retain the prior policy and comparison results. Treat a successful template deployment as confirmation of configuration delivery, not as proof that every intended object has already been processed.

Official references

Microsoft Learn: Migrate diagnostic storage retention.

Primary reference

Review the official source

Migrate from Diagnostic Settings Storage Retention to Azure Storage Lifecycle Management - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE