An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
Hello @Amanda Kitson
An HTTP 202 Accepted response only confirms that Azure accepted the deletion as an asynchronous operation; it doesn’t confirm that the deletion or cleanup deployment completed. Azure Resource Manager normally returns an Azure-AsyncOperation or Location header that can be queried until the operation reports Succeeded, Failed, or another terminal state.
There are two supported deletion paths for deployed security admin rules:
- Undeploy the security admin configuration by deploying None to the affected region, then delete the rules.
- Use a force deletion. The Azure CLI documentation states that --force initiates a background cleanup deployment before deleting a rule that belongs to a deployed configuration.
Since the rules have remained in Deleting for more than five days, the regional commit hasn’t changed, and no cleanup deployment appears to have started, this suggests that the service-side long-running operation or cleanup workflow is stalled. This is an inference from the documented process; there's no customer-accessible command that resets or clears this backend state.
If you retained the original REST response, query the URL supplied in its Azure-AsyncOperation or Location header. If it remains InProgress, returns no operation, or reports an internal failure, further retries from the portal or CLI are unlikely to expose the underlying service-side cause.
At this stage, open an Azure technical support request under Azure Virtual Network Manager through Help + support > Create a support request. An Owner, Contributor, Support Request Contributor, or equivalent custom role is required to create the request.
Include:
- Subscription ID and tenant ID
- Complete resource IDs of both rules, their rule collection, security admin configuration, and Virtual Network Manager
- East US as the affected deployment region
- UTC timestamps of the delete requests
- Activity Log operation and correlation IDs
- Any Azure-AsyncOperation or Location URLs and returned status
- The last successful regional deployment commit
- Confirmation that no resource locks are present
These details are derived from standard Azure support diagnostic practice and will allow Microsoft to trace the Network resource provider operation. Because the documented cleanup workflow hasn’t progressed, backend investigation is warranted.
References:
Remove Azure Virtual Network Manager components
Azure CLI security admin rule commands
Track asynchronous Azure operations
Create an Azure support request
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.