Recovery Services vaults holding soft-deleted backups for longer than the free 14 days
What does ZopNight detect here?
ZopNight checks Recovery Services vaults costing at least $50 a month that have soft delete enabled with a retention period longer than 14 days. Azure Backup keeps soft-deleted data free for 14 days and charges beyond that, so the saving depends on how much soft-deleted data a vault holds, which ZopNight has to measure before it quotes a figure.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1385 |
| Category | rightsizing |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | soft-delete retention > 14 days, vault cost >= $50/month |
| Source | ZopNight |
| Permissions used | Microsoft.RecoveryServices/Vaults/read · Microsoft.RecoveryServices/Vaults/backupconfig/read · Microsoft.RecoveryServices/Vaults/backupProtectedItems/read |
Where it applies
The soft-delete window and when it starts to bill
Soft delete keeps deleted backup data recoverable for a while after someone, or something, deletes it. The enhanced soft delete overview sets the default at 14 days and allows up to 180. Microsoft is explicit about cost: there is no additional charge for 14 days, and you are charged for any period beyond that.
Long windows are a legitimate defence against attacks that take weeks to notice. They are also sometimes set once, to the maximum, on vaults that only protect disposable test machines. There the extra days are storage paid for data nobody will recover.
Seeing each vault’s soft-delete setting
az backup vault list --query "[].{name:name, rg:resourceGroup}" -o table
az backup vault backup-properties show --resource-group my-rg --name my-vaultThe properties output includes the soft-delete state and duration. To see which items are currently soft-deleted, list the vault’s backup items:
az backup item list --resource-group my-rg --vault-name my-vault -o tableConditions ZopNight checks on a vault
- The vault bills at least $50 a month.
- Soft delete is enabled. Vaults where it is disabled, or where the state is unknown, are skipped.
- The soft-delete retention period is longer than the 14-day baseline.
Why a vault can pass every gate and still get no recommendation
The honest saving is the soft-deleted data volume multiplied by the backup storage rate, for the share of days above 14. The vault’s protected-item listing tells ZopNight which items are in a soft-deleted state, but it does not say how many gigabytes they occupy, and the vault’s usage summary reports total storage without separating soft-deleted from active data. ZopNight will not invent that share of the bill. So a vault that passes the three conditions is checked but does not receive a recommendation until the soft-deleted volume can be measured for it.
What the saving would be once volume is known
monthly saving = soft-deleted GB x backup storage rate per GB x (1 - 14 / soft-delete days) capped at the vault's monthly costThe formula only prices data in soft-deleted state. Active recovery points are governed by the backup policy; see Azure Recovery Vault Retention Tune for that lever.
Shortening the soft-delete window yourself
- Check compliance and security requirements before shortening the window; a long soft-delete period may be a deliberate control.
- Lower the duration, for example
az backup vault backup-properties set --resource-group my-rg --name my-vault --soft-delete-duration 14. - Review soft-deleted items and permanently remove the ones that are genuinely unwanted, if your policy allows it.