Encryption at host

prashanth miryala 21 Reputation points
2023-06-06T17:58:35.7666667+00:00

Would like to understand whether encryption at host supports on other disks (managed, Unmanaged, external) disk than OS disk\Temporary disk.

https://learn.microsoft.com/en-us/azure/virtual-machines/windows/disks-enable-host-based-encryption-powershell

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KarishmaTiwari-MSFT 18,647 Reputation points Microsoft Employee
    2023-06-07T02:03:48.73+00:00

    @prashanth miryala Thanks for posting your query on Microsoft Q&A.

    Encryption at host is supported for Managed disk.

    These are the restrictions for Disks with end-to-end encryption using encryption at host

    • Doesn't support ultra disks or premium SSD v2 managed disks.
    • Supports ephemeral OS disks but only with platform-managed keys.

    Additional Reading: https://learn.microsoft.com/en-us/azure/virtual-machines/disk-encryption-overview#comparison

    Let me know exactly what you are looking for and what's your scenario and requirements are. I can try to investigate it further.

    0 comments No comments