Disabling soft deletion for Entra resources (including managed identities) at the tenant level is not natively supported by Azure. Please try to submit a ticket to Microsoft Support to get the root reason and workaround.
How to disable soft deletion for entra resource in tenant
We generate managed identities (Entra resources), which are properly deleted upon test completion. However, Azure's soft-delete mechanism retains these resources for 30 days, during which they continue to count against our tenant quota.
Azure Automation
2 answers
Sort by: Most helpful
-
-
Sandhya Kommineni 2,730 Reputation points Microsoft External Staff Moderator
2025-11-03T03:46:03.8166667+00:00 Thanks for posting your question in Microsoft Q&A portal
Yes, Managed Identities are soft deleted for 30 days. You can view the soft deleted managed identity service principal, but you can't restore or permanently delete it and During this retention period, the soft-deleted identities still count against your tenant quota in Microsoft Entra ID. Unfortunately, this soft-delete period is fixed by Microsoft and cannot be configured or shortened.
After 30 days, these managed identities are permanently removed and stop counting against the quota. This behavior applies to managed identities as special types of service principals that are managed by Azure. As Byron Liu mentioned there isn't a supported way to bypass or purge soft-deleted managed identities before that period ends.
Refer document:
- https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/delete-recover-faq
- https://docs.azure.cn/en-us/entra/identity/managed-identities-azure-resources/managed-identities-faq
I hope the provided answer is helpful, do let me know if you have any further questions on this Please accept as Yes & upvote if the answer is helpful so that it can help others in the community.