Azure Virtual Network Manager: Stuck Deletion of Security Admin Rules — No Cleanup Deployment Initiated

Amanda Kitson 0 Reputation points
2026-09-30T14:23:51.5533333+00:00

Problem description

I am facing an issue where two security admin rules within Azure Virtual Network Manager in East US are stuck in the 'Deleting' state for over two hours after I initiated a force delete. Despite accepting the delete requests (HTTP 202) and monitoring the resources, the rules remain in the 'Deleting' state with no progress or completion events recorded in the Activity Log. Additionally, the regional deployment status still shows an older commit, indicating that the expected cleanup deployment did not start or complete. I am seeking guidance on how to resolve this stuck state and whether further backend investigation is needed.

Environment

Azure Virtual Network Manager in the East US region, involving a deployed security admin configuration with two affected rules, no resource locks detected.

What I've already tried

I have initiated force delete requests for both affected rules, which were accepted with HTTP 202. I have monitored the resources and activity logs; both rules have remained in 'Deleting' state for more than 5 days. I also checked the regional deployment status, which shows an older commit, and confirmed that no new deployment or cleanup process has started. I did not redeploy or issue additional delete commands during this period.

Current status

Currently, both rules are still stuck in the 'Deleting' state with no observable progress or errors. I am requesting assistance to diagnose why the cleanup deployment did not start or progress and to identify the next steps to resolve this issue.

Azure Virtual Network
Azure Virtual Network

An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.

0 comments No comments

2 answers

Sort by: Newest
  1. Allan Solomon Mejia 10,225 Reputation points
    2026-09-30T16:06:48.8966667+00:00

    Hello @Amanda Kitson

    An HTTP 202 Accepted response only confirms that Azure accepted the deletion as an asynchronous operation; it doesn’t confirm that the deletion or cleanup deployment completed. Azure Resource Manager normally returns an Azure-AsyncOperation or Location header that can be queried until the operation reports Succeeded, Failed, or another terminal state.

    There are two supported deletion paths for deployed security admin rules:

    • Undeploy the security admin configuration by deploying None to the affected region, then delete the rules.
    • Use a force deletion. The Azure CLI documentation states that --force initiates a background cleanup deployment before deleting a rule that belongs to a deployed configuration.

    Since the rules have remained in Deleting for more than five days, the regional commit hasn’t changed, and no cleanup deployment appears to have started, this suggests that the service-side long-running operation or cleanup workflow is stalled. This is an inference from the documented process; there's no customer-accessible command that resets or clears this backend state.

    If you retained the original REST response, query the URL supplied in its Azure-AsyncOperation or Location header. If it remains InProgress, returns no operation, or reports an internal failure, further retries from the portal or CLI are unlikely to expose the underlying service-side cause.

    At this stage, open an Azure technical support request under Azure Virtual Network Manager through Help + support > Create a support request. An Owner, Contributor, Support Request Contributor, or equivalent custom role is required to create the request.

    Include:

    • Subscription ID and tenant ID
    • Complete resource IDs of both rules, their rule collection, security admin configuration, and Virtual Network Manager
    • East US as the affected deployment region
    • UTC timestamps of the delete requests
    • Activity Log operation and correlation IDs
    • Any Azure-AsyncOperation or Location URLs and returned status
    • The last successful regional deployment commit
    • Confirmation that no resource locks are present

    These details are derived from standard Azure support diagnostic practice and will allow Microsoft to trace the Network resource provider operation. Because the documented cleanup workflow hasn’t progressed, backend investigation is warranted.

    References:

    Remove Azure Virtual Network Manager components

    Azure CLI security admin rule commands

    Track asynchronous Azure operations

    Create an Azure support request


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.