Skip to main content

Soft Delete (Azure)

A data-protection feature that retains deleted blobs, containers, or Key Vault secrets in a recoverable state for a configured retention period before permanent deletion, protecting against accidental or malicious data loss.

Soft Delete (Azure)

With soft delete enabled, a delete operation doesn't immediately destroy data — it marks it deleted and keeps it recoverable for a set number of days.

Why It Matters in Production

After a Swiggy engineer accidentally ran a script that deleted an entire blob container of restaurant menu images, soft delete meant the on-call team restored everything within minutes.

Bash
az storage account blob-service-properties update \
--account-name swiggyprodstorage --enable-delete-retention true \
--delete-retention-days 14
Tip

Soft delete only protects against delete operations — pair it with versioning if you also need to recover from accidental overwrites.

Frequently Asked Questions

What's the actual recovery window Soft Delete gives you in Azure, and what does it cost?

You configure a retention period (commonly 7-365 days depending on the service) during which a deleted blob, container, or Key Vault secret is retained in a recoverable but hidden state rather than immediately purged. Storage keeps billing you for soft-deleted data at normal rates until the retention period expires or you purge it manually, so it's not free insurance — it's a deliberate storage cost trade-off against accidental data loss.

What's a mistake teams make assuming Soft Delete protects them?

Assuming Soft Delete alone protects against a compromised account or malicious insider — an attacker with delete permissions on the storage account can often also permanently purge soft-deleted items or disable the feature itself unless you've layered on resource locks, immutability policies, or RBAC restricting who can change data protection settings. Soft Delete is designed for accidental deletion, not as a substitute for backup and access-control hardening.