An optional setting for OneLake diagnostics that locks diagnostic logs as write-once, read-many for a chosen retention period, so nobody can edit or delete them. Once set, the period cannot be reduced or undone.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Immutability in context, with comparison tables and the common traps.
Terms in this definition
- OneLake diagnostics
Turn this on for a workspace to capture OneLake access activity as JSON logs, kept in a lakehouse on the same capacity, showing who read or changed which data, when, and by what means.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
Related terms
- Recovery Services vault
Where Azure Backup and Site Recovery keep their data; it offers soft delete, immutability and multi-user authorisation, but is the wrong choice for cheaply archiving files you already have.
- WORM
Write once, read many: a model of immutability for compliance data, allowing it to be read while preventing changes or deletion.