Encryption secrets sometimes do not appear in key vault as secrets when Azure disk encryption enabled for Linux VM
We are trying to encrypt some Linux VMs using Azure disk encryption. We use the following command as we want the temporary disks to be encrypted as well and we use KEK(Key encryption key) too. az vm encryption enable --resource-group…
How to configure Azure Disk Encryption on a VM with Keyvault using Private link?
Hi All We are using Azure Disk encryption on Azure, where encryption keys are stored in KeyVault, we are planning to use Private Link for our Keyvault and has below questions 1)Does ADE supports keyvault with Private Link? 2)Is it possible to…
How to do key rotation when using Azure Disk Encryption (ADE)
Hi, We are encrypting temporary disk of a linux VMs using ADE (Azure Disk Encryption) and storing some data in temporary disk. We know that for Linux VMs ADE for temporary disk is done using --encrypt-format-all feature as shown below. az vm…
List of Azure Data Storage Services that support BYOK
Hi, Could you confirm the list of "Azure Data Storage" Services that support BYOK (Bring Your Own Key), please. Thanks
Create certificate for encrypted database failed
I'm trying to get familiar with TDE operation because one of my production database is already encrypted. Since I did not work with encryption before in SQL I found good YouTube tutorial…
Clone encrypted disk and attach it to another VM
We have a VM with all the disks encrypted and the goal is to "clone" one of the data disks and attach it to another VM (same region) We tried several approaches without success, but it would be better to achieve it quickly since we must…
AAD client/secret is not supported
Hello, i have some VM's encrypted via RSA HSM key. I want change it, but I receive this error: "Azure Disk Encryption extension version '1.1 ' without AAD client/secret is not supported on VMs previously encrypted with AAD client/secret. " …
Update to Azure Disk Encryption extension for Linux - minor version change?
Azure customers have been notified through an alert email asking them to prepare for breaking changes through an Azure Disk Encryption Extension. All the notification specifies is a general outline "to improve security, we are making potentially…
Full Version of TypeHandlerVersion in Get-AzVMExtension
Greetings, when using Get-AzVMExtension in Powershell with the AzureDiskEncryption extension, Get-AzVMExtension shows only two levels of version number (e.g., 2.2), while the portal shows 4 (e.g., 2.2.0.10). Does anyone know how to see the full version…
How many methods are provided for encryption by windows server?
How many methods are provided for encryption by windows server except EFS and BitLocker? May I ask for some examples?
Restore an Azure VM with the existing VM still running
I have a VM that has an Windows Update issue. I want to restore the Azure managed disk to about 1 month ago to see if this issue was there at that point. I don’t want to affect the original VM because its still working ok apart from the update…
Encryption state between portal and CLI varies
I have activated Azure Disk Encryption for a Windows VM which did not have any data disks. I did so by selecting "Disks to encrypt: OS and data disks" in the Azure portal. The OS disk was then shown as "SSE with PMK & ADE" in the…
Not able to set ADE on data disk for SQL VM.
Problem Statement: We had a request to create a Standard B4ms SQL VM with two standard SSD to store DB logs while creating the VM we were not able to attach Standard SSDs of 512 GB to the VM so we followed below steps Measures took: Setting up…
How to manage temporary disk with active ADE
When using the EncryptFormatAll feature to initiate ADE on a Linux VM the temporary disk will get encrypted as well. The Azure documentation states that the Azure Linux Agent therefore cannot manage swap files anymore on that disk. The documentation…
User profile - Folder Encrypted in Windows 10
Windows 10 (1809) - User profile folder has encrypted automatically by machine itself and why this is happening .In this case how can we find the root cause /log .However, the event viewer not showing related to encryption error . For eg User Outlook…
Enabling Azure Disk Encryption after Azure Migrate
I have recently migrated a virtual machine from on-premise and are trying to enable Azure Disk Encryption which fails. The error we get in 'BitLockerExtension.log' is: 2020-07-20T07:18:11.3357689Z [Info]: InitializeMachineVolumes: Encryptable OS…
How can remove azure disk encryption on vm if AzureDiskEncryption extension is deleted.
I am trying to remove encryption on one VM but mistakenly extension is deleted first . I am unable to disable encryption as I am getting errors while removing the encryption on the VM. Is there any solution for this. Below is the error. …
Disk Encryption
How long a VM will take to complete Disk encryption in Azure to enable disk encryption policy
Windows VM Data Disk Encrypted with ADE but Encryption Status shows incorrectly in Azure
I have applied ADE to my VM; both to the OS Disk and Data Disk and the encryption appears to have been applied correctly to both. However the encryption status is not being picked up correctly by Azure, in the Portal or by PowerShell command. The OS Disk…
Does Infoblox NIOS support Disk Encytion by Azure?
Could see only limited distributions of linux support Azure Disk Encyption methords as said in documentation"Linux server distributions that are not endorsed by Azure do not support Azure Disk Encryption" Could you please confirm if…