Can we add "Disk Encryption Set" managed Identity to AD groups

Venkat 60 Reputation points
2023-07-06T12:32:30.55+00:00

As part of implementing Managed Disks SSE-CMK, we are planning to associate/add "Disk Encryption Set "managed Identity to Azure security AD groups. Is it possible?

As per my knowledge I can do this with user managed Identity, but would like to know whether same possible through AD groups or not.

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,313 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
175 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,140 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,636 Reputation points Microsoft Employee
    2023-07-10T23:35:16.57+00:00

    @Venkat

    Thank you for your post and I apologize for the delayed response!

    I understand that you're leveraging Server-side encryption with Customer-managed keys and would like to know if it's possible to add a Disk Encryption Set's managed Identity to an Azure AD Security Group. To hopefully help point you in the right direction or resolve your issue, I'll share my findings below.


    Findings:
    Based off what I found, it's possible to associate a Disk Encryption Set's managed identity to an Azure AD group - When a disk encryption set is created, a system-assigned managed identity is created in Azure Active Directory (AD) and associated with the disk encryption set. For more info.

    To add the Managed Identity to an Azure AD Security Group:

    1. Create an Azure AD Group
    2. Add your Disk Encryption Set Managed Identity to the Azure AD Group
    3. Assign the required permissions to your Azure AD group.

    User's image


    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.