Skip to content

Commit 64f9a12

Browse files
Merge pull request #308075 from maneeshapujari/patch-2
Revise soft delete configuration details for Azure Backup
2 parents 367c6b6 + d27f78d commit 64f9a12

3 files changed

Lines changed: 170 additions & 105 deletions

File tree

articles/backup/backup-azure-enhanced-soft-delete-configure-manage.md

Lines changed: 114 additions & 92 deletions
Original file line numberDiff line numberDiff line change
@@ -1,101 +1,38 @@
11
---
2-
title: Configure and manage enhanced soft delete for Azure Backup
3-
description: This article describes about how to configure and manage enhanced soft delete for Azure Backup.
2+
title: Configure and manage soft delete for Azure Backup
3+
description: This article describes about how to configure and manage soft delete for Azure Backup.
44
ms.topic: how-to
55
ms.date: 05/26/2025
66
ms.service: azure-backup
77
author: AbhishekMallick-MS
88
ms.author: v-mallicka
9-
# Customer intent: As a backup administrator, I want to configure enhanced soft delete for my backup vault, so that I can protect my backup data from accidental deletion and ensure its recoverability over a specified retention period.
9+
ms.custom: references_regions
10+
# Customer intent: As a backup administrator, I want to configure soft delete for my recovery services vault or backup vault, so that I can protect my backup data from accidental deletion and ensure its recoverability over a specified retention period.
1011
---
1112

12-
# Configure and manage enhanced soft delete in Azure Backup
13+
# Configure and manage soft delete in Azure Backup
1314

14-
This article describes how to configure and use [enhanced soft delete](backup-azure-enhanced-soft-delete-about.md) to protect your data and recover backups, if they're deleted.
15+
This article describes how to configure and use [soft delete](secure-by-default.md) to protect your data and recover backups, if they're deleted.
1516

16-
>[!Note]
17-
>Once you enable enhanced soft delete by enabling soft delete state to *always-on*, you can't disable it for that vault.
18-
19-
## Prerequisites
20-
21-
Before you configure and manage enhanced soft delete on the vault, review the following prerequisites:
22-
23-
- Enhanced soft delete is supported for Recovery Services vaults and Backup vaults.
24-
- Enhanced soft delete applies to all vaulted workloads alike in Recovery Services vaults and Backup vaults. However, it currently doesn't support operational tier workloads, such as Azure Files backup, Operational backup for Blobs, and Disk and VM snapshot backups.
25-
- For hybrid backups (using MARS, DPM, or MABS), enabling always-on soft delete will disallow server deregistration and deletion of backups via the Azure portal. If you don't want to retain the backed-up data, we recommend you not to enable the *always-on soft-delete* for the vault or perform *stop protection with delete data* before the server is decommissioned.
26-
- There's no retention cost for the default soft delete duration of 14 days for vaulted backup, after which it incurs regular backup cost.
27-
28-
## Enable soft delete with always-on state
29-
30-
Soft delete is enabled by default for all new vaults you create. To make enabled settings irreversible, select **Enable Always-on Soft Delete**.
31-
32-
**Choose a vault**
33-
34-
# [Recovery Services vault](#tab/recovery-services-vault)
35-
36-
Follow these steps:
37-
38-
1. Go to **Recovery Services vault** > **Properties**.
39-
40-
1. Under **Soft Delete**, select **Update** to modify the soft delete setting.
41-
42-
:::image type="content" source="./media/backup-azure-enhanced-soft-delete/open-soft-delete-properties-blade-inline.png" alt-text="Screenshot showing you how to open Soft Delete blade." lightbox="./media/backup-azure-enhanced-soft-delete/open-soft-delete-properties-blade-expanded.png":::
43-
44-
The soft delete settings for cloud and hybrid workloads are already enabled, unless you've explicitly disabled them earlier.
45-
46-
1. If soft delete settings are disabled for any workload type in the **Soft Delete** blade, select the respective checkboxes to enable them.
47-
48-
>[!Note]
49-
>Enabling soft delete for hybrid workloads also enables other security settings, such as Multi-factor authentication and alert notification for back up of workloads running in the on-premises servers.
50-
51-
1. Choose the number of days between *14* and *180* to specify the soft delete retention period.
52-
53-
>[!Note]
54-
>- There is no cost for soft delete for *14* days. However, deleted instances in soft delete state are charged if the soft delete retention period is *>14* days. Learn about [pricing details](backup-azure-enhanced-soft-delete-about.md#pricing).
55-
>- Once configured, the soft delete retention period applies to all soft deleted instances of cloud and hybrid workloads in the vault.
56-
57-
1. Select the **Enable Always-on Soft delete** checkbox to enable soft delete and make it irreversible.
58-
59-
:::image type="content" source="./media/backup-azure-enhanced-soft-delete/enable-always-on-soft-delete.png" alt-text="Screenshot showing you how to enable a;ways-on state of soft delete.":::
17+
## Supported scenarios
18+
- Soft delete is now enforced by default, and soft delete state can no longer be modified from the Azure portal. This enforcement ensures reliable recovery from any accidental or malicious deletions.
19+
- With secure by default, soft delete is also applied at the vault level. When a vault is deleted, it automatically transitions into a soft-deleted state, enabling recovery if required. [Learn more](secure-by-default.md)
6020

61-
>[!Note]
62-
>If you opt for *Enable Always-on Soft Delete*, select the *confirmation checkbox* to proceed. Once enabled, you can't disable the settings for this vault.
21+
## Supported regions
6322

64-
1. Select **Update** to save the changes.
23+
**Secure by default with soft delete** is available in the following regions:
6524

66-
# [Backup vault](#tab/backup-vault)
67-
68-
Follow these steps:
69-
70-
1. Go to **Backup vault** > **Properties**.
71-
72-
1. Under **Soft Delete**, select **Update** to modify the soft delete setting.
73-
74-
:::image type="content" source="./media/backup-azure-enhanced-soft-delete/open-soft-delete-properties.png" alt-text="Screenshot showing you how to open soft delete blade for Backup vault.":::
75-
76-
Soft delete is enabled by default with the checkboxes selected.
77-
78-
1. If you've explicitly disabled soft delete for any workload type in the **Soft Delete** blade earlier, select the checkboxes to enable them.
79-
80-
1. Choose the number of days between *14* and *180* to specify the soft delete retention period.
81-
82-
>[!Note]
83-
>There is no cost for enabling soft delete for *14* days. However, you're charged for the soft delete instances if soft delete retention period is *>14* days. Learn about the [pricing details](backup-azure-enhanced-soft-delete-about.md#pricing).
84-
85-
1. Select the **Enable Always-on Soft Delete** checkbox to enable soft delete always-on and make it irreversible.
25+
| Vault Type | Availability Type | Regions |
26+
|--------------------------|----------------------|---------------------------------------------|
27+
| Recovery Services Vault | General Availability | East Asia |
28+
| Recovery Services Vault | Preview | All remaining Azure Public Regions |
29+
| Backup Vault | Preview | Australia East, West Central US, East Asia |
8630

87-
:::image type="content" source="./media/backup-azure-enhanced-soft-delete/enable-always-on-soft-delete-backup-vault.png" alt-text="Screenshot showing you how to enable always-on state for Backup vault.":::
31+
For **Backup Vault**, in regions other than **Australia East**, **West Central US**, and **East Asia**, you still have the option to **disable soft delete** from the Azure portal.
8832

89-
>[!Note]
90-
>If you opt for *Enable Always-on Soft Delete*, select the *confirmation checkbox* to proceed. Once enabled, you can't disable the settings for this vault.
33+
## Soft-Delete a backup item
9134

92-
1. Select **Update** to save the changes.
93-
94-
---
95-
96-
## Delete a backup item
97-
98-
You can delete backup items/instances even if the soft delete settings are enabled. However, if the soft delete is enabled, the deleted items don't get permanently deleted immediately and stays in soft deleted state as per [configured retention period](#enable-soft-delete-with-always-on-state). Soft delete delays permanent deletion of backup data by retaining deleted data for *14*-*180* days.
35+
With Secure by Default enabled, backup items can still be soft deleted and later permanently deleted based on configured retention period. However, when a backup item is deleted, it first enters a soft delete state and is retained for the configured retention period before permanent deletion. This retention window helps protect against accidental or malicious deletions by delaying permanent data removal for 14 to 180 days, allowing sufficient time to recover the deleted backup data if needed.
9936

10037
**Choose a vault**
10138

@@ -165,6 +102,9 @@ Follow these steps:
165102

166103
All recovery points now appear and the backup item changes to *Stop protection with retain data* state. However, backups don't resume automatically. To continue taking backups for this item, select **Resume backup**.
167104

105+
>[!Note]
106+
>Undeleting a soft deleted item reinstates the backup item into Stop backup with retain data state and doesn't automatically restart scheduled backups. You need to explicitly [resume backups](backup-azure-manage-vms.md#resume-protection-of-a-vm) if you want to continue taking new backups. Resuming backup also cleans up expired recovery points, if any.
107+
168108
# [Backup vault](#tab/backup-vault)
169109

170110
Follow these steps:
@@ -202,9 +142,9 @@ Here are some points to note:
202142

203143
You can undelete a container only if it's not registered to another vault. If it's registered, then you need to unregister it with the vault before performing the *undelete* operation.
204144

205-
## Delete recovery points
145+
## Soft delete recovery points
206146

207-
[Soft delete of recovery points](backup-azure-enhanced-soft-delete-about.md#soft-delete-of-recovery-points) is a part of enhanced soft delete that helps you recover any recovery points that are accidentally or maliciously deleted for some operations that could lead to deletion of one or more recovery points. Recovery points don't move to soft-deleted state immediately and have a *24 hour SLA* (same as before). The example here shows recovery points that were deleted as part of backup policy modifications.
147+
[Soft delete of recovery points](secure-by-default.md#soft-delete-of-recovery-points) helps you recover any recovery points that are accidentally or maliciously deleted for some operations that could lead to deletion of one or more recovery points. Recovery points don't move to soft-deleted state immediately and have a *24 hour SLA* (same as before). The example here shows recovery points that were deleted as part of backup policy modifications.
208148

209149
Follow these steps:
210150

@@ -242,19 +182,101 @@ Follow these steps:
242182

243183
The impacted recovery points don't have the *soft deleted* label and can't in soft-deleted state. If there are recovery points that are still beyond the increased retention duration, these would continue to be in the soft-deleted state unless the retention is further increased.
244184

245-
## Disable soft delete
185+
## Manage soft deleted vaults
186+
187+
When vaults are moved to a soft deleted state, you can view, manage and undelete them before its permanently deleted.
188+
189+
**Choose a vault**
190+
191+
# [Recovery Services vault](#tab/recovery-services-vault)
246192

247193
Follow these steps:
248194

249-
1. Go to your *vault* > **Properties**.
195+
1. Go to the *Recovery Services Vaults* in Azure portal.
250196

251-
1. On the **Properties** page, under **Soft delete**, select **Update**.
252-
1. In the **Soft Delete settings** blade, clear the **Enable soft delete** checkbox to disable soft delete.
197+
2. Go to *Manage Deleted Vaults* in the top menu to view the list of soft deleted vaults with their scheduled purge time.
198+
199+
3. Select the vault of your choice to view the overview and the soft deleted backup items inside the vault.
200+
201+
# [Backup vault](#tab/backup-vault)
202+
203+
Follow these steps:
204+
205+
1. Go to the *Backup Vaults* in Azure portal.
206+
207+
2. Go to *Manage Deleted Vaults* in the top menu to view the list of soft deleted vaults with their scheduled purge time.
208+
209+
3. Select the vault of your choice to view the overview and the soft deleted backup items inside the vault.
210+
211+
---
212+
213+
## Recover soft deleted vaults
214+
215+
If a vault and its backup items are soft-deleted, you can recover them by undeleting the vault and then restoring the backup items before permanent deletion.
216+
217+
# [Recovery Services vault](#tab/recovery-services-vault)
218+
219+
Follow these steps:
220+
221+
1. Navigate to *Recovery Services Vaults* in Azure portal.
222+
223+
2. Select **Manage Deleted Vaults** from the top menu to view the list of soft-deleted vaults along with their scheduled purge time.
224+
225+
3. Select the vault you want to undelete and review its overview and soft-deleted backup items.
226+
227+
4. Click **Undelete Vault** and confirm the vault details. This action moves the vault back to an active state.
228+
229+
5. After undeleting the vault, you must recover and undelete the backup items separately.
253230

254231
>[!Note]
255-
>- You can't disable soft delete if **Enable Always-on Soft Delete** is enabled for this vault.
256-
>- You can also use multi-user authorization (MUA) to add an additional layer of protection against disabling soft delete. [Learn more](multi-user-authorization-concept.md).
257-
>- MUA for soft delete is currently supported for Recovery Services vaults only.
232+
> - System-assigned and user-assigned managed identities are **not restored** after undeleting the Recovery Services vault. You must reassign these identities manually.
233+
> - Private endpoint connections are removed during vault deletion. After undeleting the vault, you must recreate private endpoints in the required VNet before performing operations on backup data sources or containers
234+
235+
236+
# [Backup vault](#tab/backup-vault)
237+
238+
1. Navigate to *Backup Vaults* in Azure portal.
239+
240+
2. Select **Manage Deleted Vaults** from the top menu to view the list of soft-deleted vaults along with their scheduled purge time.
241+
242+
3. Select the vault you want to undelete and review its overview and soft-deleted backup items.
243+
244+
4. Click **Undelete Vault** and confirm the vault details. This action moves the vault back to an active state.
245+
246+
>[!Note]
247+
> - When a vault is deleted, its associated **system-assigned** and **user-assigned managed identities** are removed permanently.
248+
> - During the undelete process, you have an option to assign a system-managed identity by default.
249+
> - If you **leave the checkbox selected**, the vault will regain its system identity automatically.
250+
> - If you **uncheck the checkbox**, the undelete action will succeed, but any attempt to resume backups will fail because the vault lacks an identity. In this case, you can manually assign a new managed identity to the vault after the undelete operation.
251+
252+
5. After undeleting the vault, you must recover and undelete the backup items separately.
253+
254+
---
255+
256+
## Manage customer-managed keys (CMKs) after undeletion
257+
258+
To ensure CMKs are enabled after undeleting the vault, follow these steps:
259+
260+
1. To reapply CMK settings, perform one of the following actions to activate CMK:
261+
262+
- Choose a different key and apply CMK settings and then revert back to the original CMK key.
263+
264+
- Choose a different managed identity than the identity used for CMK encryption before vault undeletion and reapply CMK settings.
265+
266+
These actions will reactivate CMK on the vault after it is undeleted.
267+
268+
## Resume backup for a soft-deleted backup item
269+
270+
To resume backup for a soft-deleted backup item, follow these steps:
271+
272+
1. Navigate to the backup instance and select **Resume Backup**.
273+
2. Choose **Grant Permissions** to ensure the associated managed identity has the required permissions.
274+
> [!NOTE]
275+
> - If permissions are not granted, the backup operation will fail.
276+
> - The **Grant Permissions** option will not be available if the vault associated with the backup instance does not have a managed identity assigned.
277+
>
278+
> To resolve this, assign the identity and configure permissions from **Identity** under the vault properties.
279+
258280

259281
## Related content
260282

@@ -264,4 +286,4 @@ For implementing other security measures on the vaults, see the following articl
264286
- [Immutable vault for Azure Backup](backup-azure-immutable-vault-concept.md).
265287
- [Private endpoints (v1 experience) for Azure Backup](private-endpoints-overview.md).
266288
- [Private endpoints (v2 experience) for Azure Backup](backup-azure-private-endpoints-concept.md).
267-
- [Secure by Default with Azure Backup (Preview)](secure-by-default.md).
289+
- [Secure by Default with Azure Backup ](secure-by-default.md).

0 commit comments

Comments
 (0)