Offline time window when enabling Encryption at Host

Nermin Pezerovic 0 Reputation points
2023-07-28T14:11:00.3633333+00:00

Good morning,

i have a question regarding enabling Encryption at Host. Currently i have the option to enable it, but the VM must be offline, so i am wondering what is the time that machine has to be offline while this process is executing? What does it depend on, VM size, type?

Also is it possible to restore the machine to another region if i Encrypted it at Host successfully? Of course if i would be using CMK, i would have to have CMK in that region as well in Key Vault.

Is there a scenario where when i enable Encryption at Host i can't take backups or i can't restore the machine properly?

Thanks in advance.

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
175 questions
{count} votes

1 answer

Sort by: Most helpful
  1. TP 98,176 Reputation points
    2023-08-11T17:05:54.37+00:00

    Hi Nermin,

    i have a question regarding enabling Encryption at Host. Currently i have the option to enable it, but the VM must be offline, so i am wondering what is the time that machine has to be offline while this process is executing? What does it depend on, VM size, type?

    A: Normally enabling Encryption at Host only takes a second or two to enable. So for the most part it is the time it takes to Deallocate the VM plus the time it takes for the VM to Start.

    Also is it possible to restore the machine to another region if i Encrypted it at Host successfully? Of course if i would be using CMK, i would have to have CMK in that region as well in Key Vault.

    A: Yes, you can restore VM using Cross Region Restore.

    Is there a scenario where when i enable Encryption at Host i can't take backups or i can't restore the machine properly?

    A: Not that I'm aware of.

    You should test the different scenarios you care about so that you are familiar with the details. For example, if you've never used Cross Region Restore you may be surprised to learn that it can take 12 hours for backup data to replicate to the secondary region. The result of this is that the restore point that is available to restore in secondary region may not be as recent as you expected.

    Please review document below for important information on restoring VMs:

    https://learn.microsoft.com/en-us/azure/backup/backup-azure-arm-restore-vms

    Please click Accept Answer if the above was helpful.

    Thanks.

    -TP

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.