Need to know about the Microsoft defender recoomedations

Mahadev, Rakesh [HAEA] 225 Reputation points
2025-02-13T17:22:46.8433333+00:00

Hello All,

I received a recommendation in defender for cloud for virtual machine as below. I need to know what are the risks and how it can be achieved.

Virtual machines and virtual machine scale sets should have encryption at host enabledWindows virtual machines should enable Azure Disk Encryption or EncryptionAtHost.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,089 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-02-13T21:19:01.49+00:00

    Hi Mahadev, Rakesh [HAEA]
    Welcome to the Microsoft Q&A Platform! Thank you for asking your question here
    Based on your query,
    General things happen If disk encryption isn’t turned on, someone could access your sensitive data if they steal the physical disks or hack the underlying hardware. This is a big risk, especially for personal or financial data, and could lead to legal issues

    To enable encryption at host for your virtual machines and virtual machine scale sets, navigate to the Azure portal, select your virtual machine or scale set, and go to the "Disks" section. Under "Encryption", set "Encryption at host" to "Enabled" and save your changes.

    For Windows virtual machines, you can enable Azure Disk Encryption or EncryptionAtHost by navigating to your Windows virtual machine in the Azure portal, selecting "Disks", and setting "Azure Disk Encryption" to "Enabled". Again, save your changes to apply the settings.

    For further detailed guidance, please refer to the following Microsoft documentation:

    Use the Azure portal to enable end-to-end encryption using encryption at host
    Azure Disk Encryption for Windows VMs

    And also, can you look into the same kind of similar question to get more about the details
    https://learn.microsoft.com/en-us/answers/questions/245460/what-are-the-cons-of-azure-disk-encryption
    https://learn.microsoft.com/en-us/answers/questions/1287847/encryption-at-host-potential-downsides

    if you have any further queries. If you need any additional assistance, please feel free to tag me in a comment, and I will be happy to help you as needed.

    If you found this information helpful and my inputs, please click an accepting the answer and "Upvote" on my post for other community members referenceUser's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.