# Do not use blob tag search as a complete inventory of previous versions

> Tags can remain attached to an older blob version without being available to the blob index query engine.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-457-do-not-use-blob-tag-search-as-a-complete-inventory-of-previous-versions/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:19+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Tags can remain attached to an older blob version without being available to the blob index query engine.

## Potentially affected

Version-enabled Azure Blob Storage accounts using indexed blob tags.

## DSE recommendation

Separate current-version tag discovery from the approved inventory of historical versions.

## Article

## Source facts

Blob index tags are retained on previous versions, but those historical tags are not sent to the index engine. A tag query therefore cannot retrieve the previous versions. When an earlier version is promoted to current, its tags become current-version tags and are passed to the index for querying.

New and edited tags can take time to appear in the index; the delay depends on the workload and traffic distribution. Microsoft’s hierarchical-namespace tag feature is a separate preview without indexing, so it should not be treated as the indexed search described here. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-manage-find-blobs).

## Applicability

Confirm that the account supports indexed tags and identify whether the requested inventory covers current data, historical versions or both. Do not turn a tag-search result into a statement about a different scope.

## DSE recommendation

DSE recommends documenting the discovery method and its version coverage beside any retention, recovery or investigation result. Use an approved version-aware inventory when the question includes historical data. Do not promote a version merely to make it searchable: that would change which version is current and should require its own recovery decision.

## Verification

In a test container, create a known version history with distinguishable tags and compare the approved version inventory with current-version search results. Allow for observed indexing delay when validating changes. Record the query, permissions, observation time and version scope. A missing historical match should trigger the appropriate version inspection, not a conclusion that the data never existed or has been fully removed.

## Official references

[Microsoft Learn: Manage and find Azure Blob data with blob index tags](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-manage-find-blobs). Source retrieved September 9, 2026.

## Primary reference

- Name: Manage and find Azure Blob data with blob index tags | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/blobs/storage-manage-find-blobs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not use blob tag search as a complete inventory of previous versions,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-457-do-not-use-blob-tag-search-as-a-complete-inventory-of-previous-versions/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
