Share via


EncryptionSetIdentity interface

The managed identity for the disk encryption set. It should be given permission on the key vault before it can be used to encrypt disks.

Properties

type

The type of Managed Identity used by the DiskEncryptionSet. Only SystemAssigned is supported for new creations. Disk Encryption Sets can be updated with Identity type None during migration of subscription to a new Azure Active Directory tenant; it will cause the encrypted resources to lose access to the keys.

userAssignedIdentities

The list of user identities associated with the disk encryption set. The user identity dictionary key references will be ARM resource ids in the form: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'.

Property Details

type

The type of Managed Identity used by the DiskEncryptionSet. Only SystemAssigned is supported for new creations. Disk Encryption Sets can be updated with Identity type None during migration of subscription to a new Azure Active Directory tenant; it will cause the encrypted resources to lose access to the keys.

type?: "None" | "SystemAssigned" | "UserAssigned" | "SystemAssigned, UserAssigned"

Property Value

"None" | "SystemAssigned" | "UserAssigned" | "SystemAssigned, UserAssigned"

userAssignedIdentities

The list of user identities associated with the disk encryption set. The user identity dictionary key references will be ARM resource ids in the form: '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'.

userAssignedIdentities?: Record<string, UserAssignedIdentitiesValue>

Property Value

Record<string, UserAssignedIdentitiesValue>