162 questions with Azure Disk Encryption tags

Sort by: Updated
2 answers One of the answers was accepted by the question author.

Rotating ADE KEK, adds two new secrets (Wrapped BEKs) for the same VM

Hello All, We enabled ADE for OS+DATA disk for two VMs (RHEL8 - with no data disk attached) with same KEK, using az vm encryption enable -n vmname -g rsgrp --key-encryption-key kek --disk-encryption-keyvault keyvault-name --volume-type ALL…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-03-08T14:28:21.167+00:00
Vasantha Raman A 21 Reputation points
accepted 2022-03-24T13:37:29.25+00:00
Vasantha Raman A 21 Reputation points
1 answer One of the answers was accepted by the question author.

application gateway and encryption aks

I have 2 very simple questions, but I don't know them. 1.- How do I know which version (v1 or v2) of application gateway I have configured? It just says: SKU: Standard 2.- AKS uses "encryption at-rest with a platform-managed key" by…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
982 questions
asked 2022-03-11T17:43:25.013+00:00
Sebastian Pacheco 156 Reputation points
commented 2022-03-15T18:00:03.993+00:00
Sebastian Pacheco 156 Reputation points
1 answer One of the answers was accepted by the question author.

Azure Disk Encryption SSE + PMK - Attached to other VM

¿If I have the right permissions to do it , the other virtual machine can access to the data? Example: same region, subscription, resource group Thanks and Best Regards

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-03-10T15:58:59.617+00:00
David Wahby 21 Reputation points
commented 2022-03-11T09:26:02.85+00:00
Alan Kinane 16,796 Reputation points MVP
1 answer

Is there a performance impact to storage accounts with infrastructure encryption enabled for double encryption of data ?

Hi All, I am thinking about enabling a storage account with infrastructure encryption enabled for double encryption of data to support a new file server that I am planning to migrate. I am curious to know if there would be a significant…

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
1,194 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,791 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
584 questions
asked 2021-02-02T13:05:54.38+00:00
RandyK 6 Reputation points
answered 2022-03-01T16:31:19.72+00:00
Schroeder, Michael (CTR) 26 Reputation points
1 answer

Please tell me which is the right way of doing disk encryption in azure windows vm.

Could you please tell me is it a right way of doing disk encryption From the vm -> Under disks section go to the disks -> open the disk -> Under settings, Encryption -> changing the encryption type and saving it. Is it a right way of doing…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-02-18T03:42:48.41+00:00
Azurelearner 1 Reputation point
commented 2022-02-18T11:52:10.803+00:00
Sumarigo-MSFT 44,336 Reputation points Microsoft Employee
5 answers One of the answers was accepted by the question author.

Getting "Caller needs data action" while enabling Azure Disk Encryption on Windows VM.

Hello All, I am getting below error while trying to enable Azure Disk Encryption for my VM. I tried with recreating VM and Key Vault both but still getting same issue. I do have full rights in Key Vault access policy and its also enabled for…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,155 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-09-29T11:24:53.267+00:00
Amjad Nagori 286 Reputation points
commented 2022-02-04T13:36:52.097+00:00
Amjad Nagori 286 Reputation points
1 answer

Double Encryption of the storage account after creation

Hi, Is it possible to enable the double encryption of the infrastructure (Storage account) after it has been created already) we don't want to delete files but just implement a double encryption on the already created storage

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-02-02T14:48:14.51+00:00
Othon Francois Dibwe 1 Reputation point
answered 2022-02-02T15:19:24.663+00:00
Sumarigo-MSFT 44,336 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Disk Encryption is not working properly in Linux VM, root folder changed to ‘/oldroot folder and unexpected behavior

Hi Team, I have enabled disk encryption for one of my Linux VM in Azure. After some time I am facing the following issues in the servers, Problems: The root '/' is been changed as '/oldroot' 2) All the user "/home" directory is been…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2020-05-14T13:13:20.333+00:00
ajkuma 23,181 Reputation points Microsoft Employee
commented 2022-01-26T08:50:51.66+00:00
Prateek Mehrotra 1 Reputation point
1 answer One of the answers was accepted by the question author.

Azure Disk Encryption /boot partition too small

Hi, We have enabled ADE (both OS and data disks) on our Ubuntu 20.04 Virtual Machines. After a few months we noticed that our VMs started crashing due to lack of space on /boot partition. On standard VM /boot directory is under root filesystem (30GB) and…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-01-14T09:50:15.787+00:00
Bartosz Suchorowski 31 Reputation points
commented 2022-01-25T10:59:58.943+00:00
Bartosz Suchorowski 31 Reputation points
4 answers

Encrypt Linux machine in Azure

Good evening everyone. We need to encrypt Linux machines running in Azure (all of them CentOS). Some of them are B1ls/B1s type instances, all of them have only OS drive. Due to prerequisites described in article…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-01-02T13:47:08.583+00:00
LuckyPhantom 1 Reputation point
answered 2022-01-21T09:19:23.037+00:00
Sumarigo-MSFT 44,336 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Is there anyware azure can recover disk/VM data?

Recently my azure windows VM got infected by MedusaLocker ransomware and all files are encryted. I don't have any backup or snapshot, Is there anyway azure have backup of disk or VM itself. kindly help me recover my data if anyone knows.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
584 questions
asked 2022-01-11T14:44:45.157+00:00
Aashir Anwar 21 Reputation points
accepted 2022-01-18T07:19:51.957+00:00
Aashir Anwar 21 Reputation points
1 answer One of the answers was accepted by the question author.

Azure VMs Bulk disk encryption for a resource group

Hi Team, I've a requirement of enabling disk encryption of more than 80 VM's in a resource group. so there any possible way to enable disk encryption in bulk rather than going one by one. Like using PowerShell and key Vault KEK method. Additionally,…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-01-02T15:00:14.603+00:00
Siva Sankararao Arudra 61 Reputation points
accepted 2022-01-04T13:52:55.17+00:00
Siva Sankararao Arudra 61 Reputation points
1 answer

Azure VM scale set boot is blocked by bitlocker

Hi all, I'm creating a VM scale set from a captured image of a VM that I pre-configured. Basic windows OS with some scripts and data pre-installed. When I created the scale set all the VM's are blocked by bitlocker asking for USB insertion. There…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Virtual Machine Scale Sets
Azure Virtual Machine Scale Sets
Azure compute resources that are used to create and manage groups of heterogeneous load-balanced virtual machines.
355 questions
asked 2021-12-14T18:25:19.77+00:00
Dave Roberts 116 Reputation points
commented 2021-12-15T17:30:00.17+00:00
Dave Roberts 116 Reputation points
1 answer

auto-encrypt file in azure storage but don't want plain file when download. Want user to decrypt locally with admin provided key

We have a case where we want to upload plain File and want azure to auto-encrypt in azure storage but we don't want it to auto decrypt while user download. We want user to decrypt locally. We are planning to provide key to each company computer and…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,791 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-12-02T19:05:52.623+00:00
AK 1 Reputation point
answered 2021-12-03T10:00:13.817+00:00
Sumarigo-MSFT 44,336 Reputation points Microsoft Employee
4 answers One of the answers was accepted by the question author.

Enabled VM Disk Encryption but some disks are not encrypted

I enabled Azure disk encryption on the VM for OS and data disks but some disks for the VM do not show encrypted. Is there any way I can force encryption on a single disk with VM encryption enabled?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
584 questions
asked 2021-11-17T18:09:24.533+00:00
Johnny Le 101 Reputation points
commented 2021-11-27T11:40:09.673+00:00
Ronen Ariely 15,096 Reputation points
2 answers One of the answers was accepted by the question author.

How to enable Azure Disk Encryption Windows Failover cluster disk

hello Everyone, I have a requirement which I need to apply Azure Disk Encryption on all the virtual machine disks, while this is a straight forward process; however I am not able to apply ADE on cluster disk (a shared disk between two cluster machines,…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-11-21T17:27:34.947+00:00
Qi-Jian-Huang-DevOps 166 Reputation points
commented 2021-11-22T01:42:44.657+00:00
Qi-Jian-Huang-DevOps 166 Reputation points
1 answer One of the answers was accepted by the question author.

Use Encryption at Host on VM using Managed disk

Hi Experts, We are currently using managed disks on Azure which by default provides SSE with PMK. The requirement is to have End to End encryption, hence we would be choosing Encryption at Host option. Questions What happens to the existing…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
584 questions
asked 2021-11-11T11:18:17.227+00:00
Srinidhi S 21 Reputation points
accepted 2021-11-15T15:15:59.613+00:00
Srinidhi S 21 Reputation points
1 answer

Attached data disks not getting encrypted for linux VM

Hello Guys, I have deployed linux VM of size E16s_v3. Also a data disk of size 256Gb was attached. BYOK (Basically Customer managed keys) was used to encrypt the VM. But at the end only VM OS disk was encrypted and attached data disks wasn't encrypted.…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-10-07T17:23:04.183+00:00
Riyaz Ahmed SK 1 Reputation point
answered 2021-10-07T21:08:17.447+00:00
deherman-MSFT 34,196 Reputation points Microsoft Employee
1 answer

What are the Microsoft Recommended GPO's for handling Azure Disk Encryption Recovery Keys for Windows?

Hello. I have a Windows Server 2016 VM that is Domain Joined within Azure. I'm wondering what are the Microsoft recommended ADDS GPO's for Azure Disk Encryption to handle the recovery keys with the following below I'm considering based on my research: …

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-09-30T19:47:11.227+00:00
Michael Dubissette 1 Reputation point
answered 2021-10-01T16:54:28.983+00:00
Michael Dubissette 1 Reputation point
1 answer

Azure Disk Encryption Extension Fails

Hi, I am having issues with ADE extension on our Azure VMs. After the installation of the extension, everything looks good, disks are encrypted etc. But during the backup operations, using Azure Backup, ADE extension starts throwing error message. Disks…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,333 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2021-09-28T07:51:51.567+00:00
Ayhan Güler 6 Reputation points
commented 2021-09-30T07:15:49.477+00:00
Ayhan Güler 6 Reputation points