Do not use blob tag search as a complete inventory of previous versions

Tags can remain attached to an older blob version without being available to the blob index query engine.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Tags can remain attached to an older blob version without being available to the blob index query engine.

Potentially affected

Version-enabled Azure Blob Storage accounts using indexed blob tags.

DSE recommendation

Separate current-version tag discovery from the approved inventory of historical versions.

Source facts

Blob index tags are retained on previous versions, but those historical tags are not sent to the index engine. A tag query therefore cannot retrieve the previous versions. When an earlier version is promoted to current, its tags become current-version tags and are passed to the index for querying.

New and edited tags can take time to appear in the index; the delay depends on the workload and traffic distribution. Microsoft’s hierarchical-namespace tag feature is a separate preview without indexing, so it should not be treated as the indexed search described here. Microsoft Learn.

Applicability

Confirm that the account supports indexed tags and identify whether the requested inventory covers current data, historical versions or both. Do not turn a tag-search result into a statement about a different scope.

DSE recommendation

DSE recommends documenting the discovery method and its version coverage beside any retention, recovery or investigation result. Use an approved version-aware inventory when the question includes historical data. Do not promote a version merely to make it searchable: that would change which version is current and should require its own recovery decision.

Verification

In a test container, create a known version history with distinguishable tags and compare the approved version inventory with current-version search results. Allow for observed indexing delay when validating changes. Record the query, permissions, observation time and version scope. A missing historical match should trigger the appropriate version inspection, not a conclusion that the data never existed or has been fully removed.

Official references

Microsoft Learn: Manage and find Azure Blob data with blob index tags. Source retrieved September 9, 2026.

Primary reference

Review the official source

Manage and find Azure Blob data with blob index tags | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE