Hello @Freestone ,
- Yes, migrating domain-joined systems will require careful planning and likely multiple maintenance windows. You can expect downtime several minutes depending on how quickly you recreate the VM and rejoin the domain.
Doing this manually can be quite cumbersome and can be error prone too thus automation is highly recommended. You can use powershell or Azure tools (ARM/Bicep templates) to script domain unjoin, save network configuration and automate VM creation with--encryption-at-host trueand domain join. - Any VM or disk still using ADE by the retirement date becomes inaccessible once platform support ends. This includes running VMs, stopped VMs, and backups that rely on ADE. To avoid data loss, all ADE-encrypted disks must be decrypted or migrated before the deadline. I'd suggest treat mid-2028 as your effective cut-off and ensure no critical data exists only in old ADE-encrypted backups—restore and re-back them up using the new encryption method while support is still available.