Tag: Azure Disk Encryption

Implement and configure disk encryption (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Implement and configure disk encryption


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Disk encryption protects data stored on virtual machine disks from unauthorized access. In Azure, disk encryption is an important defense-in-depth control for infrastructure-as-a-service workloads, especially when virtual machines process sensitive, regulated, or confidential information.

For the SC-500 exam, you should understand:

  • The difference between server-side encryption and guest-based disk encryption.
  • How Azure Disk Encryption uses BitLocker or DM-Crypt.
  • How Azure Key Vault stores and protects encryption keys and secrets.
  • The difference between Azure Disk Encryption and encryption at host.
  • How to configure disk encryption for Windows and Linux virtual machines.
  • How to use customer-managed keys.
  • How to protect encryption keys and avoid operational problems.
  • The retirement considerations for Azure Disk Encryption.

Why Disk Encryption Is Important

Virtual machine disks can contain:

  • Operating system files.
  • Application data.
  • Database files.
  • Temporary files.
  • Credentials and configuration data.
  • Logs and diagnostic information.
  • Cached information.
  • Sensitive customer or business data.

If a disk, snapshot, backup, or storage medium is accessed without authorization, encryption helps prevent the data from being read in its unencrypted form.

Disk encryption helps protect data:

  • At rest.
  • In snapshots and images.
  • In operating system and data volumes.
  • In temporary disks, depending on the encryption method and configuration.
  • During storage or infrastructure access scenarios.

Disk encryption does not replace:

  • Identity and access management.
  • Network security.
  • Endpoint protection.
  • Application-level authorization.
  • Database security.
  • Backup security.
  • Monitoring and auditing.

It is one layer in a defense-in-depth security strategy.


Azure Disk Encryption Concepts

Server-Side Encryption

Azure managed disks are encrypted at rest by default using platform-managed keys. This is commonly called server-side encryption, or SSE.

Azure managed disks, snapshots, and images are transparently encrypted using 256-bit Advanced Encryption Standard encryption. The encryption is handled by the Azure platform and does not normally require changes inside the virtual machine.

Server-side encryption protects data persisted in Azure Storage. However, it does not necessarily encrypt every type of data temporarily stored on the virtual machine host, such as:

  • Temporary disk data.
  • OS disk caches.
  • Data disk caches.

For stronger end-to-end protection, consider encryption at host.


Azure Disk Encryption

Azure Disk Encryption, or ADE, encrypts disks from inside the guest operating system.

It uses:

  • BitLocker for Windows virtual machines.
  • DM-Crypt for Linux virtual machines.

Azure Disk Encryption integrates with Azure Key Vault to manage disk-encryption keys and secrets.

Azure Disk Encryption can encrypt:

  • The operating system disk.
  • Data disks.
  • Temporary disks when the appropriate volume option is selected.

ADE uses the virtual machine’s operating system and CPU resources to perform guest-based encryption.

Windows

For Windows virtual machines, Azure Disk Encryption uses BitLocker to provide full disk encryption for the OS disk and data disks. The temporary disk can also be encrypted when the VolumeType setting is All.

Linux

For Linux virtual machines, Azure Disk Encryption uses DM-Crypt to provide full disk encryption for the OS disk and data disks. The temporary disk can be encrypted when using the EncryptFormatAll option.


Encryption at Host

Encryption at host provides encryption on the physical Azure VM host before data is written to Azure Storage.

It encrypts:

  • Temporary disks.
  • OS disk caches.
  • Data disk caches.
  • Data flowing from the VM host to Azure Storage.

Encryption at host provides end-to-end encryption for VM data and does not use the VM’s CPU for encryption. It therefore avoids the performance impact associated with guest-based encryption.

Encryption at Host Compared with Azure Disk Encryption

FeatureAzure Disk EncryptionEncryption at Host
Encryption locationInside the guest OSOn the Azure VM host
Windows technologyBitLockerAzure platform encryption
Linux technologyDM-CryptAzure platform encryption
Uses VM CPUYesNo
Encrypts OS and data disksYesYes
Encrypts temporary disksWith appropriate configurationYes
Encrypts disk cachesNot comprehensivelyYes
Uses Azure Key VaultYesMay use platform-managed or customer-managed keys
Recommended for new deploymentsGenerally noGenerally yes
Migration considerationExisting ADE workloads must be migratedPreferred modern approach

Microsoft states that Azure Disk Encryption is scheduled for retirement on September 15, 2028. Until that date, existing ADE workloads can continue operating, but after the retirement date encrypted disks will fail to unlock following VM reboots. New workloads should use encryption at host, and existing ADE workloads should be migrated before the retirement date.


Azure Disk Encryption and Azure Key Vault

Azure Key Vault is used to control and manage the encryption keys and secrets associated with Azure Disk Encryption.

A typical arrangement includes:

  1. The VM’s disks are encrypted using BitLocker or DM-Crypt.
  2. Encryption secrets are stored in Azure Key Vault.
  3. The VM or Azure platform accesses the required secrets during boot and disk-unlock operations.
  4. Key Vault access policies or permissions control access to the encryption material.

Key Vault Requirements

When configuring a Key Vault for Azure Disk Encryption:

  • The Key Vault must be in the same region as the VM.
  • The Key Vault must be in the same Microsoft Entra tenant as the VM.
  • The Key Vault must be enabled for disk encryption.
  • Required access permissions must be configured.
  • Networking rules must allow the required access.
  • Soft-delete should be enabled.
  • The encryption keys and secrets must not be deleted or disabled while they are still required.

Azure documentation specifically requires the Key Vault and VM to be colocated in the same region and tenant so encryption secrets do not cross regional boundaries.

Enabling Key Vault for Disk Encryption

When creating a Key Vault with Azure CLI, the relevant option is:

az keyvault create \
--name "<key-vault-name>" \
--resource-group "<resource-group-name>" \
--location "eastus" \
--enabled-for-disk-encryption

For an existing Key Vault, you can enable the setting with:

az keyvault update \
--name "<key-vault-name>" \
--resource-group "<resource-group-name>" \
--enabled-for-disk-encryption true

The equivalent Azure PowerShell parameter is:

-EnabledForDiskEncryption

If the Key Vault firewall is enabled, the required trusted-service access and network configuration must also be considered.


Encryption Keys and Key Encryption Keys

Disk Encryption Secrets

Azure Disk Encryption uses encryption secrets associated with the guest-based encryption process. These secrets are stored in Azure Key Vault.

Protecting the Key Vault is therefore critical. If an attacker gains unauthorized access to the encryption secrets, the security value of disk encryption can be significantly reduced.

Key Encryption Key

A key encryption key, or KEK, provides an additional layer of protection.

When a KEK is used:

  1. Azure Disk Encryption generates or uses disk-encryption secrets.
  2. The secrets are wrapped using the KEK.
  3. The wrapped secrets are stored in Key Vault.
  4. The KEK remains protected in Key Vault.

A KEK can be:

  • Generated in Azure Key Vault.
  • Imported into Azure Key Vault.
  • Protected by a customer-controlled key-management process supported by Key Vault.

Azure Disk Encryption requires an RSA key for a KEK; elliptic-curve keys are not supported for this purpose. Versioned KEK URLs are also required.

Important KEK Considerations

  • Do not delete the KEK while encrypted VMs depend on it.
  • Do not disable the key version currently being used.
  • Retain the correct key version.
  • Ensure administrators have appropriate Key Vault permissions.
  • Monitor key expiration and rotation.
  • Test recovery procedures before changing encryption keys.

Customer-Managed Keys

Azure managed disks can use either:

  • Platform-managed keys.
  • Customer-managed keys.

With customer-managed keys, the organization controls the key used to encrypt and decrypt managed disk data.

Customer-managed keys can help organizations meet requirements related to:

  • Regulatory compliance.
  • Key ownership.
  • Key rotation.
  • Key revocation.
  • Separation of duties.
  • Internal security policies.
  • Customer-controlled cryptographic material.

Customer-managed keys depend on managed identities and Microsoft Entra ID. If a subscription, resource group, or managed disk is moved to another Microsoft Entra tenant, the associated managed identity may not transfer, which can cause customer-managed-key access to stop working.


Azure Disk Encryption Prerequisites

Before enabling ADE, verify the following.

Supported VM

The virtual machine must use:

  • A supported operating system.
  • A supported VM size.
  • A supported disk configuration.
  • A supported Azure region.

Not every VM size, operating system image, or disk configuration supports every encryption scenario.

Key Vault

The Key Vault must:

  • Exist in the same region as the VM.
  • Be in the same Microsoft Entra tenant.
  • Be enabled for disk encryption.
  • Have the required permissions.
  • Be reachable according to its networking configuration.
  • Have soft-delete enabled where required.

Networking

The VM must be able to reach the services required for encryption and key retrieval.

If Key Vault network restrictions are enabled, validate:

  • Private endpoint configuration, if used.
  • Virtual network integration.
  • Firewall rules.
  • Trusted Microsoft services settings.
  • DNS resolution.
  • Routing.
  • Required outbound connectivity.

Backup and Recovery

Before encrypting a production VM:

  • Verify that a recent backup exists.
  • Confirm that the backup can be restored.
  • Document the Key Vault and key dependencies.
  • Record the encryption configuration.
  • Test recovery of encrypted disks.
  • Ensure the required keys and secrets are retained.

Encryption without a recovery plan can create a situation in which data is technically protected but operationally inaccessible.


Configuring Azure Disk Encryption

Azure Disk Encryption can be configured through:

  • The Azure portal.
  • Azure CLI.
  • Azure PowerShell.
  • Infrastructure-as-code templates.

The general process is:

  1. Identify the VM and its operating system.
  2. Confirm that the VM is supported.
  3. Create or select a Key Vault.
  4. Enable Key Vault for disk encryption.
  5. Configure Key Vault permissions and networking.
  6. Optionally create a KEK.
  7. Enable disk encryption on the VM.
  8. Select the volumes to encrypt.
  9. Monitor the encryption operation.
  10. Verify the encryption status.
  11. Test restart and recovery behavior.

Encrypting Windows VMs

For a Windows VM, Azure Disk Encryption uses BitLocker.

A typical configuration decision is the volume type:

  • OS — encrypt only the operating system disk.
  • Data — encrypt data disks.
  • All — encrypt the OS disk, data disks, and temporary disk where supported.

The exact supported options depend on the operating system, VM configuration, and current Azure tooling.

After enabling encryption, verify:

  • The OS disk is encrypted.
  • Data disks are encrypted.
  • The intended temporary-disk behavior is configured.
  • The VM can restart successfully.
  • The VM can retrieve the required encryption secrets.
  • The Key Vault remains available.

Encrypting Linux VMs

For a Linux VM, Azure Disk Encryption uses DM-Crypt.

Before enabling encryption, verify:

  • The Linux distribution is supported.
  • The filesystem configuration is supported.
  • The VM uses a supported disk layout.
  • Required packages and extensions are available.
  • The VM has sufficient free space and stable connectivity.
  • The encryption operation will not conflict with existing encryption.

The EncryptFormatAll option can be used for scenarios in which additional volumes, including temporary storage, must be encrypted. However, this option must be used carefully because formatting operations can result in data loss if applied to disks containing existing data.

After enabling encryption, verify:

  • The OS disk is encrypted.
  • Data disks are encrypted.
  • Mount points remain available.
  • The VM restarts correctly.
  • Required secrets can be retrieved from Key Vault.
  • Applications can access their data.

Azure Disk Encryption Extension

Azure Disk Encryption is commonly implemented through the Azure Disk Encryption extension.

The extension performs encryption-related operations inside the guest operating system and communicates with the Azure platform and Key Vault as required.

When troubleshooting, inspect:

  • VM extension status.
  • Extension provisioning state.
  • Azure Activity Log.
  • VM boot diagnostics.
  • Guest operating system logs.
  • Key Vault audit logs.
  • Key Vault access configuration.
  • Network connectivity.
  • Encryption status reported by Azure.

A failed extension operation may indicate:

  • Unsupported operating system.
  • Unsupported VM size.
  • Incorrect Key Vault configuration.
  • Missing permissions.
  • Network restrictions.
  • Invalid key or secret references.
  • Insufficient disk space.
  • Existing encryption conflicts.
  • An unsupported disk layout.
  • A disabled or expired key.

Monitoring and Verifying Encryption

After configuring disk encryption, do not assume that the operation succeeded simply because the deployment completed.

Verify the actual encryption state.

Useful verification methods include:

  • Azure portal encryption status.
  • Azure CLI.
  • Azure PowerShell.
  • VM extension status.
  • Operating system commands.
  • Azure Resource Graph queries.
  • Azure Policy compliance.
  • Defender for Cloud recommendations.
  • Azure Activity Log.
  • Key Vault audit logs.

For Windows, verify BitLocker status inside the operating system.

For Linux, verify the DM-Crypt and encrypted-volume configuration.

Also verify that:

  • The VM can reboot.
  • Encrypted disks unlock correctly.
  • Applications can read and write data.
  • Backup operations continue to work.
  • Key Vault access remains functional.
  • Key rotation or key-version changes do not break access.

Protecting Encryption Keys

Disk encryption is only as strong as the protection applied to its keys and secrets.

Key Vault Security Recommendations

Use the following practices:

  • Apply least-privilege access.
  • Restrict administrative access.
  • Use Microsoft Entra role-based access control or appropriate access policies.
  • Enable logging and monitoring.
  • Enable soft-delete.
  • Use purge protection where appropriate.
  • Restrict network access.
  • Prefer private endpoints when appropriate.
  • Monitor key and secret access.
  • Separate key-management duties from VM administration.
  • Avoid embedding secrets in scripts or templates.
  • Avoid granting broad access to the entire Key Vault.
  • Maintain recovery procedures for keys and secrets.

Key Rotation

Key rotation must be planned carefully.

Important considerations include:

  • Which key version is currently used?
  • Is the new key version supported by the encryption configuration?
  • Will the old key remain available?
  • Will disabling the old key prevent VM startup?
  • Are backups dependent on the old key?
  • Has the rotation process been tested?

For Azure Disk Encryption, automatic Key Vault key rotation is not fully compatible with the way ADE continues to use the original encryption key. Rotating a key does not necessarily break ADE, but disabling the original key can prevent the VM from unlocking its disks.


Azure Disk Encryption Retirement

Azure Disk Encryption is scheduled for retirement on September 15, 2028.

The important implications are:

  • Existing ADE workloads can continue operating until the retirement date.
  • ADE-enabled workloads must be migrated before the retirement date.
  • After retirement, encrypted disks may fail to unlock after VM reboots.
  • New VM deployments should generally use encryption at host.
  • Backups of ADE-enabled VMs must also be considered during migration.

The recommended modern approach is to use:

  • Encryption at host for new VM workloads.
  • Customer-managed keys where organizational requirements justify them.
  • Confidential VM capabilities when stronger confidential-computing protections are required.

Azure Disk Encryption Versus Encryption at Host: Exam Perspective

A common SC-500 exam scenario may ask which solution should be used for a new VM deployment.

Choose encryption at host when the requirement is to:

  • Encrypt temporary disks.
  • Encrypt OS and data disk caches.
  • Protect data end-to-end from the VM host to Azure Storage.
  • Avoid using the VM CPU for encryption.
  • Use the recommended modern disk-encryption approach.

Choose Azure Disk Encryption mainly when:

  • You are managing an existing ADE-encrypted workload.
  • A legacy workload specifically requires BitLocker or DM-Crypt-based guest encryption.
  • You are preparing to migrate an existing ADE workload.
  • The scenario explicitly requires guest-based encryption.

Remember that standard managed-disk server-side encryption is already enabled by default. The question is often whether the scenario requires protection beyond ordinary encryption at rest.


Common Mistakes to Avoid

Mistake 1: Assuming server-side encryption encrypts everything on the VM host

Server-side encryption protects data persisted in Azure Storage. It does not necessarily provide the same coverage as encryption at host for temporary disks and disk caches.

Mistake 2: Treating Azure Disk Encryption and encryption at host as identical

They operate at different layers:

  • ADE encrypts inside the guest operating system.
  • Encryption at host encrypts on the physical VM host.

Mistake 3: Deleting or disabling the old key after rotation

An encrypted VM may still depend on the original key version.

Mistake 4: Ignoring Key Vault networking

A VM may fail to unlock its disks if it cannot reach Key Vault.

Mistake 5: Encrypting without a tested recovery plan

If keys or secrets are lost, encrypted data may become inaccessible.

Mistake 6: Using EncryptFormatAll without understanding its effect

Formatting or encrypting all volumes can cause data loss if existing data disks are not handled correctly.

Mistake 7: Assuming encryption eliminates the need for access controls

Encryption does not replace RBAC, network security, identity protection, monitoring, or application security.

Mistake 8: Deploying new workloads with ADE without considering retirement

New workloads should generally use encryption at host because ADE is scheduled for retirement.


Key Takeaways

For the SC-500 exam, remember these points:

  1. Azure managed disks are encrypted at rest by default using platform-managed keys.
  2. Azure Disk Encryption uses BitLocker for Windows and DM-Crypt for Linux.
  3. Azure Disk Encryption integrates with Azure Key Vault.
  4. ADE encrypts from inside the guest operating system.
  5. Encryption at host encrypts data on the physical VM host.
  6. Encryption at host also protects temporary disks and disk caches.
  7. Encryption at host does not use the VM CPU for encryption.
  8. ADE requires careful management of Key Vault keys and secrets.
  9. A KEK provides an additional layer of protection for encryption secrets.
  10. The Key Vault and VM must be in the same region and Microsoft Entra tenant for ADE.
  11. Disabling or deleting a required key can prevent a VM from unlocking its disks.
  12. ADE is scheduled for retirement on September 15, 2028.
  13. New workloads should generally use encryption at host.
  14. Encryption must be verified after deployment.
  15. Encryption is only one component of defense in depth.

Practice Exam Questions

Question 1

A company is deploying new Azure virtual machines. The security team requires encryption of the OS disk, data disks, temporary disks, and disk caches. The solution should not use the VM’s CPU for encryption.

Which solution should you recommend?

A. Azure Disk Encryption
B. Encryption at host
C. BitLocker configured manually inside the VM
D. Azure Storage service-side encryption only

Correct answer: B

Explanation: Encryption at host encrypts temporary disks, OS and data disk caches, and data flowing from the VM host to Azure Storage. It performs encryption on the host rather than using the VM’s CPU.


Question 2

Which technology does Azure Disk Encryption use to encrypt the operating system and data disks of a Linux virtual machine?

A. BitLocker
B. Azure Storage encryption
C. DM-Crypt
D. Transparent Data Encryption

Correct answer: C

Explanation: Azure Disk Encryption uses DM-Crypt for Linux virtual machines. BitLocker is used for Windows virtual machines.


Question 3

An administrator is configuring a Key Vault for Azure Disk Encryption. Which requirement must be satisfied?

A. The Key Vault must be in a different region from the VM
B. The Key Vault must be in the same region and Microsoft Entra tenant as the VM
C. The Key Vault must be publicly accessible from the internet
D. The Key Vault must use only platform-managed keys

Correct answer: B

Explanation: Azure Disk Encryption requires the Key Vault and VM to be in the same region and Microsoft Entra tenant so that encryption secrets do not cross regional boundaries.


Question 4

What is the primary purpose of a key encryption key in an Azure Disk Encryption configuration?

A. To encrypt the VM’s network traffic
B. To replace BitLocker or DM-Crypt
C. To encrypt the Azure subscription
D. To wrap and protect the disk-encryption secrets stored in Key Vault

Correct answer: D

Explanation: A key encryption key, or KEK, provides an additional protection layer by wrapping the disk-encryption secrets before they are stored in Azure Key Vault.


Question 5

A company rotates a Key Vault key used by an existing Azure Disk Encryption VM. What should the administrator do before disabling the old key version?

A. Confirm that the VM and its backups no longer depend on the old key version
B. Delete the old key immediately
C. Disable the entire Key Vault
D. Restart the VM before changing the key

Correct answer: A

Explanation: Azure Disk Encryption may continue using the original encryption key. Disabling or deleting that key can prevent the VM from unlocking its disks after a restart.


Question 6

Which statement best describes server-side encryption for Azure managed disks?

A. It requires BitLocker to be installed in the guest operating system
B. It is automatically applied to data persisted in Azure Storage
C. It encrypts only temporary disks
D. It requires a customer-managed key in every deployment

Correct answer: B

Explanation: Azure managed disks are encrypted at rest by default using server-side encryption and platform-managed keys. Customer-managed keys are optional.


Question 7

A Linux administrator wants to encrypt all supported volumes, including temporary storage, using Azure Disk Encryption. Which configuration should the administrator investigate?

A. EncryptFormatAll
B. UseBitLocker
C. EnableTrustedLaunch
D. EnableTDE

Correct answer: A

Explanation: For Linux VMs, the EncryptFormatAll option can be used to encrypt additional volumes, including temporary storage. It must be used carefully because formatting operations can cause data loss.


Question 8

A new Azure VM must have encrypted temporary disks and encrypted OS and data disk caches. Which encryption option is most appropriate?

A. Azure Disk Encryption with only the OS volume selected
B. Manual encryption of the data disks inside the guest OS
C. Encryption at host
D. Azure SQL Transparent Data Encryption

Correct answer: C

Explanation: Encryption at host protects temporary disks and OS and data disk caches in addition to providing encryption for VM data flowing to Azure Storage.


Question 9

Which statement about Azure Disk Encryption is correct?

A. It uses BitLocker for Windows and DM-Crypt for Linux
B. It is performed only by Azure Storage and does not involve the guest OS
C. It does not require Azure Key Vault
D. It encrypts all network traffic leaving the VM

Correct answer: A

Explanation: Azure Disk Encryption is guest-based. It uses BitLocker on Windows and DM-Crypt on Linux, and it integrates with Azure Key Vault for encryption keys and secrets.


Question 10

A security engineer is planning a new VM deployment in 2026. Which recommendation is most appropriate regarding Azure Disk Encryption?

A. Use ADE for every new VM because it is the preferred long-term solution
B. Avoid all forms of disk encryption because managed disks are automatically encrypted
C. Use encryption at host for new workloads and plan migration for existing ADE workloads
D. Use only manual BitLocker configuration inside the guest operating system

Correct answer: C

Explanation: Azure Disk Encryption is scheduled for retirement on September 15, 2028. Microsoft recommends encryption at host for new workloads and migration of existing ADE-enabled workloads before the retirement date.


Go to the SC-500 Exam Prep Hub main page