Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
A vault cannot be deleted while it still has dependencies. For Azure Backup vaults, the most common blockers are:
- Protected data sources still exist in the vault.
- Backup data still exists.
- For Recovery Services vaults, items may still be in soft-deleted state for 14 days after deletion.
- Registered storage accounts, protected servers, backup management servers, or private endpoints may still be attached.
If this is a Recovery Services vault, use this order:
- In the Azure portal, open the vault and select Overview > Delete.
- In Properties > Security Settings, disable Soft Delete and Security Features if the portal allows it.
- Check for soft-deleted backup items. If any exist, either wait until they are permanently deleted after 14 days, or undelete them and delete them again so they are permanently removed.
- Go to Backup Items and for every item, select Stop Backup and then Delete Backup Data.
- Go to Backup Infrastructure and unregister:
- Protected Servers
- Backup Management Servers
- Storage Accounts
- Go to Settings > Networking > Private access and remove any private endpoints.
- Return to the vault and delete it.
If this is a Backup vault, use this order:
- Open the vault.
- Go to Backup Instances and delete all listed items.
- Check all Datasource type filter options so no hidden backup instance or policy is missed.
- After no items remain, select Delete on the vault dashboard.
Important: deleting a vault is destructive and cannot be undone. All backup data and backup items associated with the protected resources are permanently deleted.
If all dependencies are already removed and a Recovery Services vault still fails to delete, retry from the portal, then use the Azure Resource Manager client method described in the documentation.
References: