Key Vault access policy setting (enabled-for-disk-encryption) without which Azure Disk Encryption can't store keys and secrets in the vault; the vault also has to be in the same region as the VM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Disk Encryption for volume encryption in context, with comparison tables and the common traps.
Terms in this definition
- Key Vault access policy
Single entry in the legacy Key Vault model that gives one user, group, app or managed identity chosen operations on keys, secrets or certificates, applying to the entire vault.
- Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
See Azure Disk Encryption for volume encryption in the full glossary