Does azurerm_management_lock works for blobs and container

ADM_Vineeth Siripuram 20 Reputation points
2023-03-14T17:38:02.7866667+00:00

when i try to create lock for storage account level its working fine and we are unable to delete storage account , but when i try to delete container within same storage account it is providing an overide option to remove lock and delete container and when i try to delete blob iam able to delete blob directly after configuring lock for storage account,how i can reslove this issue?is there any way to create locks for storage account?

Azure Storage
Azure Storage
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
{count} votes

Answer accepted by question author
  1. shiva patpi 13,376 Reputation points Microsoft Employee Moderator
    2023-03-14T23:15:15.35+00:00

    Hello @ADM_Vineeth Siripuram ,

    Lock will be used only to lock the parent resources , in this scenario only storage accounts will be locked from deletion. It can't be used to lock individual blobs or containers within an Azure Storage account. 
    

    i.e. locking a storage account does not protect containers or blobs within that account from being deleted or overwritten. For more information about how to protect blob data, see Data protection overview. ( See below links)

    Moreover , to lock individual blobs or containers within an Azure Storage account, you can either use Shared Access Signatures (SAS) with appropriate permissions, or use Azure role-based access control (RBAC) to manage access to the storage account and its contents. You can also use Azure Policy to enforce specific rules and restrictions on the storage account and its contents.

    Additional information available here:

    https://learn.microsoft.com/en-us/azure/storage/blobs/data-protection-overview

    Data Protection options: (Container Soft delete , Blob Soft Delete , Blob versioning etc)

    https://learn.microsoft.com/en-us/azure/storage/blobs/data-protection-overview#overview-of-data-protection-options

    User's image

    Regards,

    Shiva.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.