Hi,
Microsoft has put in in the security best practices for AVD.
https://learn.microsoft.com/en-us/azure/virtual-desktop/security-guide
I also do it as a default to increase the security of any AVD environment.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
we already enabled ADE on Azure VMs disks based on CloudCheckR tool recommendations.
But now, we need suggestions whether we should also enable ADE (Azure Disk Encryptions) on AVD (Azure Virtual Desktops)? Or not required if any justification, since we’ve around 70+ AVDs are in place.
Hi,
Microsoft has put in in the security best practices for AVD.
https://learn.microsoft.com/en-us/azure/virtual-desktop/security-guide
I also do it as a default to increase the security of any AVD environment.
@M Hemant Kumar Welcome to Microsoft Q&A Forum, Thank you for posting your query here!
Enabling Azure Disk Encryption (ADE) on Azure Virtual Desktops (AVD) is a good security practice to protect the data stored on the virtual desktops. ADE uses industry-standard encryption to encrypt the data at rest on the virtual desktops, which helps to prevent unauthorized access to the data.
Enabling ADE on AVD is not mandatory, but it is recommended to protect sensitive data stored on the virtual desktops. If your organization has compliance or regulatory requirements that mandate the use of encryption for data at rest, then enabling ADE on AVD is necessary to meet those requirements.
However, whether you should enable ADE on AVD depends on several factors, including your organization's security requirements, compliance needs, and risk tolerance. Here are some considerations to help you make an informed decision:
Enabling ADE on AVD can be done using the Azure portal or PowerShell. You can follow the steps in this document to enable ADE on AVD: Encrypt virtual machine disks with Azure Disk Encryption for Windows VMs.
You should test the performance impact of enabling ADE on AVD before enabling it in production.
Enabling ADE on AVD requires a key vault to store the encryption keys. You should ensure that the key vault is properly secured and access to the key vault is restricted to authorized users.
This article describes steps you can take as an admin to keep your customers' Azure Virtual Desktop deployments secure.
Please let us know if you have any further queries. I’m happy to assist you further.
Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.