Purge protection is an optional Key Vault behavior and is not enabled by default.
Purge protection can only be enabled once soft-delete is enabled. It can be turned on via CLI or PowerShell.
Keys could be purged from the vault without protection
Enable purge protection for key vaults
The following example will fail the azure-keyvault-no-purge check.
The following example will pass the azure-keyvault-no-purge check.