162 questions with Azure Disk Encryption tags

Sort by: Updated
4 answers

"code":"NotSupported","message":"Azure Disk Encryption extension version '1.1 ' without AAD client/secret is not supported on VMs previously encrypted with AAD client/secret."

I am getting this error when I try to enable disk encryption in my Azure VM - I checked the other thread which answer this but it is not solving the problem. This is the first time ADE is being enabled on this VM and I am not aware if this was encrypted…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
995 questions
asked 2023-02-20T13:00:44.11+00:00
MILIND 1 Reputation point
edited the question 2023-04-22T07:14:57.1+00:00
Sumarigo-MSFT 44,001 Reputation points Microsoft Employee
3 answers

Create CMK encryption for azure disk, with private endpoint for azure key vault

For the azure disks, when we enabling CMK encryption , we create a azure disk encryption set and associate it the key generated from key vault and this is working fine. now the azure VM starts with CMK encryption and works fine. Our requirement is…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,259 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-03-23T10:22:02.4766667+00:00
MS Techie 2,681 Reputation points
answered 2023-04-04T02:18:02.3533333+00:00
MS Techie 2,681 Reputation points
1 answer

How to leverage Azure Encryption for MYSQL DB

Hi Team, We have explicitly encrypted some PII Data at our MySQL DB. This is causing some issues while connecting to our Database and populate it else where with decryption needed always. Is there a way we can leverage this to the Azure MySQL where i…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Database for MySQL
Azure Database for MySQL
An Azure managed MySQL database service for app development and deployment.
725 questions
Azure ISV (Independent Software Vendors) and Startups
Azure ISV (Independent Software Vendors) and Startups
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.ISV (Independent Software Vendors) and Startups: A Microsoft program that helps customers adopt Microsoft Cloud solutions and drive user adoption.
89 questions
asked 2022-05-10T04:08:54.053+00:00
Koteswara Pentakota 71 Reputation points
edited the question 2023-03-02T09:38:36.3166667+00:00
AnuragSingh-MSFT 20,431 Reputation points
1 answer

Migrate Platform Managed Keys to Customer Managed keys

Hi, We have several windows and linux azure VMs with disk encyrption being Platform managed keys. Around 100 disks How to collectively migrate those disks from Platform Managed Keys to Customer Managed Keys. We plan to store those CMK keys in…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,259 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-01-30T11:29:47.1633333+00:00
MS Techie 2,681 Reputation points
edited a comment 2023-02-28T12:33:00.5833333+00:00
MS Techie 2,681 Reputation points
1 answer

I am trying to encrypt disks in my Azure Linux VM(CentOS 7) with some critical data, how can I do it?

I am trying to encrypt disks in my Azure Linux VM(CentOS 7) with some critical data, how can I do it?

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-02-01T13:59:00.6833333+00:00
Infra Leads 0 Reputation points
commented 2023-02-17T21:53:10.8533333+00:00
SaiKishor-MSFT 17,206 Reputation points
1 answer

Key auto-rotation not compatible with Azure Disk Encryption

Hi all, on https://learn.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-key-vault?tabs=azure-portal#azure-disk-encryption-and-auto-rotation it is said that: Although Azure Key Vault now has key auto-rotation, it…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-01-06T08:28:59.417+00:00
Anonymous
edited the question 2023-02-09T05:46:39.19+00:00
srbhatta-MSFT 8,546 Reputation points Microsoft Employee
3 answers

Logging for for storage account customer managed key rotation

I followed this guide https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview to setup CMK. I can see from storage account properties and change analysis tool that new key version was automatically configured. I could not…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,735 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-12-19T15:57:55.517+00:00
Janne Kujanpää 181 Reputation points
edited the question 2023-02-05T08:45:35.14+00:00
Sumarigo-MSFT 44,001 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Communication between VM OS disk and Compute is unencrypted?

Hi. I am trying to fix one of Azure Security recommendations "Virtual machines should encrypt temp disks, caches, and data flows between Compute and Storage resources". This recommendation gets triggered on VM that does not have not temp disk…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,259 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-02-02T07:53:38.56+00:00
RM 20 Reputation points
edited the question 2023-02-02T12:52:56.3+00:00
Tarun Krishna Mikkilineni-MSFT 0 Reputation points
1 answer

PMK / CMK keys

I know when you create a CMK for vm encryption you create a KV that a DES policy will pull from. Thus, if I spin up / deploy 1,000 vm's that a particular DES, all 1,000 will have they same encryption key. I know you can create multiple KV/DES…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-12-06T18:01:33.827+00:00
Az Student 1 Reputation point
commented 2023-01-25T16:03:21.3633333+00:00
Mike Berry 0 Reputation points
2 answers One of the answers was accepted by the question author.

Not able to encrypt for OS disk in the VM

I have navigated to VM--> Disks--> Additional settings --> I have chosen OS disk and also chosen respective Key vault and key--> after saving it is giving below error. Please suggest

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-12-31T11:53:09.033+00:00
sns 9,226 Reputation points
accepted 2023-01-07T03:48:18.327+00:00
sns 9,226 Reputation points
2 answers

Azure Encryption at host

I have configured Encryption (SSE with CMK) on Azure disk. Now I'm getting a Microsoft defender recommendation, saying that "Virtual machines and virtual machine scale sets should have encryption at host enabled" How to enable encryption at…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-12-18T21:01:03.077+00:00
Mahavir Saroj 201 Reputation points
commented 2023-01-05T19:00:22.123+00:00
TP 78,666 Reputation points
0 answers

Azure Disk Encryption for SF - Performance, Downtime, Key Vault Authentication & Request Rate

Hi team, We're trying to enable the Azure Disk encryption extension for our SF clusters. I've few doubts if you could answer- Will there be any performance impact after these changes on the compute and boot time? Will there be any…

Azure Service Fabric
Azure Service Fabric
An Azure service that is used to develop microservices and orchestrate containers on Windows and Linux.
252 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-12-01T06:44:00.66+00:00
Jaspreet Singh 6 Reputation points Microsoft Employee
commented 2023-01-04T20:48:05.657+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Can a managed disk with server-side encryption using platform managed keys be exported and imported to a VM on a different tenant. Or, are PMKs tenant specific?

Hi, Just looking at pros and cons of server-side encryption using platform managed keys. Specifically, I'm trying to confirm whether disks that are encrypted with SSE using PMKs can be decrypted in ANY Azure tenant, e.g.. if SSE encrypted disk is…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
582 questions
asked 2022-12-02T13:57:49.86+00:00
Gavin Chisholm 21 Reputation points
accepted 2022-12-21T15:27:25.22+00:00
Gavin Chisholm 21 Reputation points
1 answer One of the answers was accepted by the question author.

Resizing Root Encrypted Azure linux VM

Hi, I upgraded Ubuntu VM OSDisk size from 64 GB to 80 GB by Portal. Now I need to resize root filesystem due to already 100% usage. I tried to resize /dev/sda1 using fdisk and reboot. The problem is after reboot I can't log in…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-10-15T08:07:58.13+00:00
Nurdin 21 Reputation points
accepted 2022-10-21T09:18:18.127+00:00
Nurdin 21 Reputation points
1 answer

Are Azure API Management configurations, policies stored encrypted on Azure platform?

In Azure API Management are the configurations such as policies, e.g. SOAP to REST conversion, IP whitelisting, stored encrypted on Azure platform?

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
1,796 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-10-21T02:22:41.173+00:00
Alan L 1 Reputation point
answered 2022-10-21T04:52:16.797+00:00
Dillon Silzer 54,746 Reputation points
0 answers

Azure Disk Encryption only on OS Disk

i have a short Question about Azure Disk Encryption. I have activated it on aditional Settings and have configured the Option "OS and Data Disk". When i now look at the Diks i can see that only the OS diks is encrypted. I have…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,259 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-10-17T12:40:34.96+00:00
Philipp Gerber 251 Reputation points
commented 2022-10-20T06:30:35.64+00:00
Philipp Gerber 251 Reputation points
3 answers One of the answers was accepted by the question author.

Data encryption keys managment

Hi all, I'm trying to understand if with flexible postgreSQL Database, volume encryption can be configured in a way in which keys are managed by me and not by the system, using a key vault or something similar... I've found that encryption (similar…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Database for PostgreSQL
asked 2022-07-13T11:43:38.783+00:00
Oprandi, Simone 21 Reputation points
commented 2022-10-12T05:55:34.893+00:00
Julian Schallenmüller 1 Reputation point
2 answers One of the answers was accepted by the question author.

Disk Encryption support

Hello, we are considering disk encryption with our own keys. What are the options of troubleshooting the potential issues by MS Support Engineer if any operation fail? Does have MS Support engineer access to my Key Vault or keys? What happened if I…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-09-22T06:54:43.997+00:00
Gerhart Jan 21 Reputation points
accepted 2022-10-05T06:24:08.13+00:00
Gerhart Jan 21 Reputation points
1 answer One of the answers was accepted by the question author.

Is SAN encryption and Bitlocker disk encryption same?

Dear All If i do disk encryption with BitLocker in Windows server is SAN encryption needed for data protection. I want to do it on premises server not in azure. Sorry i have to tags azure-disk-encryption as don't find any other encryption…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-09-29T09:38:13.88+00:00
Mohammad Imtiaz Kabir 21 Reputation points
accepted 2022-10-05T05:35:33.68+00:00
Mohammad Imtiaz Kabir 21 Reputation points
2 answers One of the answers was accepted by the question author.

Azure Disk Encryption for Windows VMs - Where are the keys?

We encrypt all of our Windows VMs with Azure Disk Encryption, and back them up with Azure Backup. We know the process on how to encrypt VMs and the requirements, etc. We recently had to restore a file from an encrypted disk. Since single file…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,144 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-07-14T19:51:33.213+00:00
CarmeloLoPresti-2973 61 Reputation points
accepted 2022-10-04T17:46:45.757+00:00
CarmeloLoPresti-2973 61 Reputation points