SEV-A URGENT: Accidental VM Deletion – Partial Disk Presence – Arc SQL Resources Still Visible – Immediate Recovery Assistance Required

Silvia Sasso 20 Punti di reputazione
2026-06-11T14:40:40.8233333+00:00

Earlier today, a critical virtual machine (PFDev3) hosting our development environment was accidentally deleted in the West Europe region.

This VM contained:

  • Full development environment
  • Multiple SQL Server instances
  • Associated application workloads

At the time of deletion:

  • No backups or snapshots were configured
  • Data disks and network configuration were also deleted

Current Observations (Inconsistent State)

Despite the deletion, the environment shows a partially inconsistent resource state:

  • Some managed disks still appear in the subscription
  • Azure Arc–enabled SQL Server instances and databases are still visible and reporting as "Succeeded"/online
  • Certain related resources (NIC, public IP, NSG, etc.) remain present
  • However, the underlying compute (VM) and parts of storage/network configuration appear missing

This suggests a potential partial deletion or delayed resource cleanup scenario


Business Impact

  • Loss of primary development environment
  • Potential loss of critical SQL data
  • No immediate restore path due to lack of backups

Given the recency of the incident (occurred today), this is being treated as Severity A (business-critical outage).


Urgent Questions / Assistance Required

We kindly request immediate support to clarify and assist with the following:

Recovery Possibilities

  • Is it still possible to recover the deleted VM or associated managed disks?
    • Are there internal or backend recovery mechanisms available shortly after deletion?
    Retention / Soft-Delete Behavior
    - Does Azure provide any temporary retention or soft-delete capability for:
    
          - Virtual machines
    
                - Managed disks
    
                      - Related compute resources
    
                      Rollback Feasibility
    
                         - Given the deletion occurred only a few hours ago, is there any possibility of:
    
                               - Rolling back the deletion
    
                                     - Reconstructing the VM from existing artifacts
    
                                     Arc SQL Visibility
    
                                        - Why are Azure Arc SQL instances and databases still visible and reporting as active?
    
                                           - Does this indicate underlying data still exists and may be recoverable?
    
                                           Immediate Actions Guidance
    
                                              - What actions should we avoid to prevent permanent data loss?
    
                                                 - What steps should we take immediately to maximize recovery probability?
    

Supporting Evidence (Extract)

Below is a relevant subset from az resource list showing:

  • Remaining network resources
  • Azure Arc SQL instances and databases
  • Some disk artifacts still present

Shell

az resource list --subscription <redacted> -g SviluppoDevOps -o table

Mostra più linee

(Full output available in original submission if needed)


Key Remaining Resources Detected

  • Managed disks (e.g., PFDev3_DataDisk_0, PFDev3_OsDisk_*)
  • Azure Arc SQL instances:
    • PFDev3_SQL2022
      • PFDev3_SQL2025
        • PFDev3
        • Numerous SQL databases still listed under Arc
        • Network interface: pfdev3446
        • Public IP and NSG resources

Request

Given the criticality and time sensitivity, we request:

  • Immediate escalation to Azure engineering (compute/storage)
  • Guidance on possible backend recovery paths
  • Confirmation of any recovery window still available

We are available to provide additional details or execute recovery steps immediately upon guidance.

Thank you for your urgent support.Earlier today, a critical virtual machine (PFDev3) hosting our development environment was accidentally deleted in the West Europe region.

This VM contained:

  • Full development environment
  • Multiple SQL Server instances
  • Associated application workloads

At the time of deletion:

  • No backups or snapshots were configured
  • Data disks and network configuration were also deleted

Current Observations (Inconsistent State)

Despite the deletion, the environment shows a partially inconsistent resource state:

  • Some managed disks still appear in the subscription
  • Azure Arc–enabled SQL Server instances and databases are still visible and reporting as "Succeeded"/online
  • Certain related resources (NIC, public IP, NSG, etc.) remain present
  • However, the underlying compute (VM) and parts of storage/network configuration appear missing

This suggests a potential partial deletion or delayed resource cleanup scenario


Business Impact

  • Loss of primary development environment
  • Potential loss of critical SQL data
  • No immediate restore path due to lack of backups

Given the recency of the incident (occurred today), this is being treated as Severity A (business-critical outage).


Urgent Questions / Assistance Required

We kindly request immediate support to clarify and assist with the following:

Recovery Possibilities

  • Is it still possible to recover the deleted VM or associated managed disks?
    • Are there internal or backend recovery mechanisms available shortly after deletion?
    Retention / Soft-Delete Behavior
    - Does Azure provide any temporary retention or soft-delete capability for:
    
          - Virtual machines
    
                - Managed disks
    
                      - Related compute resources
    
                      Rollback Feasibility
    
                         - Given the deletion occurred only a few hours ago, is there any possibility of:
    
                               - Rolling back the deletion
    
                                     - Reconstructing the VM from existing artifacts
    
                                     Arc SQL Visibility
    
                                        - Why are Azure Arc SQL instances and databases still visible and reporting as active?
    
                                           - Does this indicate underlying data still exists and may be recoverable?
    
                                           Immediate Actions Guidance
    
                                              - What actions should we avoid to prevent permanent data loss?
    
                                                 - What steps should we take immediately to maximize recovery probability?
    

Supporting Evidence (Extract)

Below is a relevant subset from az resource list showing:

  • Remaining network resources
  • Azure Arc SQL instances and databases
  • Some disk artifacts still present

Shell

az resource list --subscription <redacted> -g SviluppoDevOps -o table

Mostra più linee

(Full output available in original submission if needed)


Key Remaining Resources Detected

  • Managed disks (e.g., PFDev3_DataDisk_0, PFDev3_OsDisk_*)
  • Azure Arc SQL instances:
    • PFDev3_SQL2022
      • PFDev3_SQL2025
        • PFDev3
        • Numerous SQL databases still listed under Arc
        • Network interface: pfdev3446
        • Public IP and NSG resources

Request

Given the criticality and time sensitivity, we request:

  • Immediate escalation to Azure engineering (compute/storage)
  • Guidance on possible backend recovery paths
  • Confirmation of any recovery window still available

We are available to provide additional details or execute recovery steps immediately upon guidance.

Thank you for your urgent support.

SQL Server | Altro
SQL Server | Altro

Funzionalità e argomenti aggiuntivi di SQL Server non coperti da categorie specifiche

0 commenti Nessun commento

Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.