Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
Also called ADE.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Disk Encryption in context, with comparison tables and the common traps.
Terms in this definition
- Retire
Strips corporate data, managed apps and MDM profiles from a device while keeping personal data, which is the key difference from a Wipe in Intune.
- BitLocker
Full-volume encryption built into Windows; drives used with Azure Import/Export are protected with AES-256 BitLocker.
- DM-Crypt
Azure Disk Encryption encrypts the disks of Linux VMs by using this kernel subsystem.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Write Accelerator
Available only on M-series VMs, this option for Premium SSD disks reduces write latency for database logs. Disks using it don't support ADE.
Related terms
- Azure Disk Encryption for volume encryption
Key Vault access policy setting (enabled-for-disk-encryption) without which Azure Disk Encryption can't store keys and secrets in the vault; the vault also has to be in the same region as the VM.
- Azure Virtual Machines for deployment
Access policy option on a Key Vault (enabled-for-deployment) that permits Microsoft.Compute to pull certificates, kept as secrets, into VMs at creation time. Azure Disk Encryption doesn't rely on this setting.
- Backup Management Service
Service application of Azure Backup; to back up VMs encrypted with Azure Disk Encryption, it needs access to the vault's keys and secrets, granted by an access policy or a Key Vault role.
- Enable access to Azure Virtual Machines for deployment
Advanced Key Vault access policy that allows virtual machines to fetch certificates held as secrets. Azure Disk Encryption does not require it.
- Encryption at host
VM setting that encrypts caches, temp disks and ephemeral OS disks on the physical host, so data reaches storage already encrypted. It is incompatible with Azure Disk Encryption, which it is recommended to replace.
- Key encryption key
Optional Key Vault RSA key whose job is to wrap, or encrypt, a second encryption key such as the secret used by Azure Disk Encryption. Its versioned key URL identifies it.
- Set-AzVMDiskEncryptionExtension
Turns on Azure Disk Encryption for a virtual machine from Az PowerShell. Its key vault has to be in the VM's own subscription and region.
- Trusted Microsoft services
An exception in the Key Vault firewall that lets approved services, among them Azure Backup, Azure Disk Encryption and Resource Manager template deployment, access the vault regardless of network.