More Info:

Ensure that Soft Delete feature is enabled for your Microsoft Azure Storage blob objects.

Risk Level

Medium

Address

Security

Compliance Standards

CISAZURE, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of not having Soft Delete enabled for Azure Blob Storage, you can follow the below steps using the Azure console:

  1. Open the Azure portal and navigate to the storage account that needs to be updated.

  2. Click on the “Configuration” tab in the left-hand menu.

  3. Scroll down to the “Blob service” section and click on “Data protection”.

  4. Under “Soft delete”, toggle the switch to “Enabled”.

  5. Set the “Retention period” to the desired number of days for which you want to retain the deleted data.

  6. Click on “Save” to apply the changes.

After following these steps, Soft Delete will be enabled for your Azure Blob Storage and any deleted data will be retained for the specified retention period.