How to recover a deleted resource group containing User-Assigned Managed Identities?

Sivakami Subramaniam 40 Reputation points Microsoft Employee
2026-06-09T18:31:22.8166667+00:00

A resource group in my subscription was accidentally deleted on June 3, 2026. It contained 2 User-Assigned Managed Identities that are used by deployment pipelines to push container images to Azure Container Registries.

I've attempted the following recovery steps:

  • Queried the Entra ID recycle bin (GET /directory/deletedItems/microsoft.graph.servicePrincipal) for the underlying service principals — they were permanently purged and not found, even though deletion was only 6 days ago (within the 30-day soft-delete window).
  • Checked Azure Resource Graph resourcechanges — confirmed the 2 MIs were in the RG but the beforeSnapshot doesn't retain the principalId or role assignment details.
  • Checked orphaned role assignments on the target ACRs — too many orphaned entries from other prior deletions to identify which ones belonged to these identities.

Questions:

  1. Is there any way to recover a deleted resource group and its User-Assigned Managed Identities with the original principalIds preserved?
  2. Why would the service principals for User-Assigned MIs be permanently purged from the Entra recycle bin immediately upon deletion, rather than being soft-deleted for 30 days?
  3. Is there any other method to retrieve the original principalIds or role assignments for deleted managed identities?
Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2026-06-09T20:54:51.6566667+00:00

Hello @Sivakami Subramaniam No, you can't recover a deleted resource group. However, you might be able to restore some recently deleted resources. Refer this: https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/delete-resource-group?tabs=azure-powershell#can-i-recover-a-deleted-resource-group

Also regarding user managed identities, Unfortunately, once a user-assigned managed identity is deleted, it cannot be restored.

If the User-Assigned Managed Identities have been deleted, any associated RBAC role assignments are generally removed as well. Azure RBAC does not provide a built-in mechanism to retrieve or restore the historical role assignment mapping for a deleted managed identity. To determine the previous permissions, you would need to rely on historical sources such as Azure Activity Logs, Log Analytics/SIEM data, deployment templates, or other audit records that were captured before the identity was deleted.

If the assistance was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

Answer accepted by question author
Amira Bedhiafi 43,046 Reputation points MVP Volunteer Moderator
2026-06-09T19:09:30.1966667+00:00

Hello Sivakami !

Thank you for posting on MS Learn Q&A.

You cannot recover the deleted resource group or restore the User-Assigned Managed Identities with the original principalIds preserved because deleted resource group itself cannot be recovered, only some individual resource types have their own soft delete or recovery behavior. User-assigned managed identities are not one of the recoverable Azure resource types in practice.

https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/delete-resource-group

A User-Assigned Managed Identity creates a special Microsoft Entra service principal behind the scenes.

https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview

Managed identity service principals may be visible in deleted items for 30 days, but they cannot be restored or permanently deleted by customers.

https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/delete-recover-faq

Also if you delete and recreate a managed identity, the recreated identity gets a different principal ID.

https://learn.microsoft.com/en-us/azure/role-based-access-control/troubleshooting

So the practical recovery is:

# Recreate the resource group
az group create \
  --name <rg-name> \
  --location <region>
# Recreate the user-assigned managed identity
az identity create \
  --resource-group <rg-name> \
  --name <identity-name>
# Get the new principalId
NEW_PRINCIPAL_ID=$(az identity show \
  --resource-group <rg-name> \
  --name <identity-name> \
  --query principalId \
  -o tsv)
# Assign ACR push permission again
ACR_ID=$(az acr show \
  --name <acr-name> \
  --resource-group <acr-rg-name> \
  --query id \
  -o tsv)
az role assignment create \
  --assignee-object-id "$NEW_PRINCIPAL_ID" \
  --assignee-principal-type ServicePrincipal \
  --role AcrPush \
  --scope "$ACR_ID"

For the missing original principalId check these places,but treat them as /audit recovery only not identity recovery:

# Check deleted managed identity service principals in the correct tenant
az rest --method GET \
  --url "https://graph.microsoft.com/v1.0/directory/deletedItems/microsoft.graph.servicePrincipal?\$select=id,displayName,servicePrincipalType,appId,deletedDateTime&\$top=999"

Filter results where servicePrincipalType == "ManagedIdentity". Even if found, this only helps identify the old object ID it does not allow restore.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.