VM setting that encrypts caches, temp disks and ephemeral OS disks on the physical host, so data reaches storage already encrypted. It is incompatible with Azure Disk Encryption, which it is recommended to replace.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Encryption at host in context, with comparison tables and the common traps.
Terms in this definition
- Physical
Describes the concrete, real-world parts that put a logical architecture into effect.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.