162 questions with Azure Disk Encryption tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

How to enable key vault permission for disk encryption set using Azure Python SDK API calls?

I am setting up disk encryption using a key vault, but I'm unable to grant permission to the key vault after creating the Disk Encryption Set (DES). The overview section of the DES shows a warning that reads: "To associate a disk, image, or snapshot…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,141 questions
Azure Cloud Services
Azure Cloud Services
An Azure platform as a service offer that is used to deploy web and cloud applications.
651 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-10-20T13:42:34.8966667+00:00
Prem Jha 25 Reputation points
commented 2023-11-02T06:23:35.8066667+00:00
Prem Jha 25 Reputation points
1 answer

VM protected with ADE and the key in Key Vault expires - expected outcome?

Hello, We have Azure Disk Encryption enabled on our VMs. The encryption key is stored in an Azure key vault and there is a corporate policy that keys and secrets must have expiry dates. I tested to see what would happen to a VM when the key expired. The…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,244 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-09-20T13:40:03.17+00:00
mij2020 366 Reputation points
commented 2023-09-28T19:25:59.14+00:00
mij2020 366 Reputation points
1 answer One of the answers was accepted by the question author.

Az Powershell to get disk encryption is pmk or cmk

The azure vm disk can be cmk or pmk encrypted. Which azure powershell command let's me find the disk encryption type is pmk or cmk. (Note - i am only bothered about pmk and cmk encryption and not other encryption)

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,244 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-09-19T22:25:50.0666667+00:00
MS Techie 2,681 Reputation points
accepted 2023-09-20T06:08:28.1366667+00:00
MS Techie 2,681 Reputation points
1 answer One of the answers was accepted by the question author.

Is UEFI lock required for Encrypted Azure VM

Hello, We are asked to apply a New Security Control –“ Protective Process Light for LSASS should be enabled with a UEFI lock.” We are using Gen2 Azure Windows Server 2019 and selected 'Standard' as security type when the VMs were created. The OS disk has…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,244 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-09-15T01:35:00.01+00:00
Farzana Mustafa 81 Reputation points
accepted 2023-09-18T23:44:02.0133333+00:00
Farzana Mustafa 81 Reputation points
1 answer

Facing error while encrypting a VM os and data disk using ADE

Facing error while encrypting a virtual machine(windows server 2016) disk through ADE. Although have given all the access roles to the key vaults and also enabled the desired permssions in vault access policy and all the resource access for vault but…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,244 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
asked 2023-08-02T10:43:07.4633333+00:00
Ishan Saxena 20 Reputation points
commented 2023-09-05T04:17:59.43+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
1 answer

Error creating a azurerm_storage_encryption_scope for a storage account with terraform

Hi all i am working on a terraform script for creating my infra on azure. i am facing some issue. i want to set encryption_scope for my storage container but i don't find any reference for setting for storage container. i found the reference for…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,733 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-08-09T17:01:58.9766667+00:00
Vikrant 20 Reputation points
commented 2023-09-04T13:33:25.0733333+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
2 answers

Deleting multiple unattached azure disks in bulk

My question is broken into two sections, related to Azure disks that are unattached/ no owner. 1s question: Besides using the Azure portal to check which disks have no owner associated with them, is there another way I can check or run a script for…

Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
233 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
asked 2022-04-05T13:44:40.763+00:00
Razzi29 331 Reputation points
edited the question 2023-08-25T06:12:40.48+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
2 answers

Azure Files failing transactions

We have recently configured Azure Files and successfully migrated one of our many department directories. We are experiencing no significant issues and no user complaints to this point. As part of the configuration we enabled Diagnostic Settings…

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
1,176 questions
Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
233 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,733 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
asked 2022-05-25T17:18:11.403+00:00
Hauck, Michael 1 Reputation point
edited the question 2023-08-25T06:12:39.84+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
1 answer

Storage account - Infrastructure level encryption

Hello, I want to create a storage account and enable infrastructure encryption. From MS documentation is states that: "Infrastructure-level encryption **relies on Microsoft-managed keys and always uses a separate key.**"…

Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
233 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
asked 2021-12-20T06:40:18.367+00:00
Angela Calborean 71 Reputation points
edited the question 2023-08-25T06:12:39.4+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
2 answers

Serviso gratuito 12 meses

Ola, me cadastrei na Microsoft azure a 1 mes aproximado venho utilizando a maquina, no inicio me falava que eu tinha 12 meses de acesso gratuito, mas acabou que recebi uma mensagem falando que acabou meus créditos, oque preciso fazer ?

Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
233 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Lab Services
Azure Lab Services
An Azure service that is used to set up labs for classrooms, trials, development and testing, and other scenarios.
282 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
asked 2021-11-04T03:30:39.78+00:00
samuel lacerda 6 Reputation points
edited the question 2023-08-25T06:12:38.9433333+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
1 answer

Offline time window when enabling Encryption at Host

Good morning, i have a question regarding enabling Encryption at Host. Currently i have the option to enable it, but the VM must be offline, so i am wondering what is the time that machine has to be offline while this process is executing? What does it…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-07-28T14:11:00.3633333+00:00
Nermin Pezerovic 0 Reputation points
commented 2023-08-22T13:51:27.8866667+00:00
TP 78,506 Reputation points
2 answers

Azure Disk encryption on Azure virtual desktop

we already enabled ADE on Azure VMs disks based on CloudCheckR tool recommendations. But now, we need suggestions whether we should also enable ADE (Azure Disk Encryptions) on AVD (Azure Virtual Desktops)? Or not required if any justification, since…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,382 questions
asked 2023-07-26T20:06:23.97+00:00
M Hemant Kumar 20 Reputation points
commented 2023-08-02T14:57:56.0666667+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
1 answer

Do Enabling Customer Managed Keys will have any effect while accessing data using SAS keys?

We are trying to implement customer managed keys in storage accounts. So i do understand that we might have to make few code changes while connecting to Storage account as mentioned in the article…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,733 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure FastTrack
Azure FastTrack
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.FastTrack: This tag is no longer in use. Please use 'Azure Startups' instead.
74 questions
asked 2023-07-21T07:08:39.1766667+00:00
Sachin Vettiyattil-FT 41 Reputation points
commented 2023-08-02T14:49:33.7133333+00:00
Sumarigo-MSFT 43,911 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Azure Disk Encryption - Failing due to SSL/TLS secure connection

Hi All, Our Azure Disk Encyrption keeps failing to due to an error saying a secure SSL/TLS connection could not be established, from my troubleshooting it seems it is our proxy that is causing it to fail as once uninstalled it works fine. Does anyone…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-07-28T09:13:53.8666667+00:00
Ben Woodman 106 Reputation points
accepted 2023-08-01T08:08:42.4266667+00:00
Ben Woodman 106 Reputation points
1 answer One of the answers was accepted by the question author.

SERVER SIDE ENCRYPTION - PMK TO CMK

We have several linux azure VMs and storage accounts with SSE encryption being Platform managed keys. The existing infra built using terraform. Now we are planning to convert all managed disks and storage accounts to SSE CMK. The question is, Does pmk to…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,141 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,733 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-07-18T21:14:20.5733333+00:00
Venkat 60 Reputation points
accepted 2023-07-26T01:29:54.2833333+00:00
Venkat 60 Reputation points
1 answer One of the answers was accepted by the question author.

What does "SSE with PMK & ADE" mean?

I understand what Server Side Encryption and Azure Disk Encryption mean and how you can turn them on. I don't understand that when I turn on the ADE (BitLocker) for a (windows) VM's OS disk, the OS disk encryption says "SSE with PMK &…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2022-10-05T04:00:12.477+00:00
Anuj Jain 71 Reputation points
commented 2023-07-22T07:38:42.6266667+00:00
Aditya Garg 61 Reputation points
1 answer

Azure Policy to remediate/Enforce "Encryption at Host"

Hello Community, I observe the in built Azure Policy here to audit VMs for "encryption at host" setting(end to end encryption using PMK or CMK). "Virtual machines and virtual machine scale sets should have encryption at host…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
803 questions
asked 2023-06-26T16:52:04.5333333+00:00
Aditya Garg 61 Reputation points
answered 2023-07-20T03:58:13.29+00:00
Jesse Loudon 336 Reputation points MVP
1 answer One of the answers was accepted by the question author.

Can we add "Disk Encryption Set" managed Identity to AD groups

As part of implementing Managed Disks SSE-CMK, we are planning to associate/add "Disk Encryption Set "managed Identity to Azure security AD groups. Is it possible? As per my knowledge I can do this with user managed Identity, but would like to…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,141 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,771 questions
asked 2023-07-06T12:32:30.55+00:00
Venkat 60 Reputation points
accepted 2023-07-18T22:03:14.34+00:00
Venkat 60 Reputation points
3 answers One of the answers was accepted by the question author.

What RSA Size should i use to enable ADE on Azure VMs?

Hi, When i try to enable ADE on our Azure Virtual Machines they keep failing due to an error: VM has reported a failure when processing extension 'AzureDiskEncryption'. Error message: "[2.3.0.0] Failed to enable Azure Disk Encryption on the VM with…

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
asked 2023-07-12T14:27:26.3966667+00:00
Ben Woodman 106 Reputation points
accepted 2023-07-14T07:38:20.2766667+00:00
Ben Woodman 106 Reputation points
1 answer

How to update a generalized disk in Azure VM

I am facing an issue where I am unable to upgrade the disk size of my generalized VM through the Azure portal. The portal does not show me the update option under the disk section. I have tried using az-cli, but I am encountering permission issues and…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,244 questions
Azure VMware Solution
Azure VMware Solution
An Azure service that runs native VMware workloads on Azure.
321 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
Azure Disk Storage
Azure Disk Storage
A high-performance, durable block storage designed to be used with Azure Virtual Machines and Azure VMware Solution.
581 questions
Azure Virtual Machine Scale Sets
Azure Virtual Machine Scale Sets
Azure compute resources that are used to create and manage groups of heterogeneous load-balanced virtual machines.
353 questions
asked 2023-07-04T07:47:07.93+00:00
devidinesh7890@gmail.com 0 Reputation points
commented 2023-07-14T05:56:31.98+00:00
Prrudram-MSFT 22,486 Reputation points