Block storage disks for VMs whose underlying storage accounts Azure looks after. The only redundancy choices are LRS and ZRS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Managed disks in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Redundancy
So that hardware failures, datacentre outages or a regional disaster cannot destroy data, Azure Storage keeps multiple copies: only in the primary region with LRS and ZRS, or in a secondary region as well with GRS and GZRS.
- LRS
Locally redundant storage, the lowest-cost redundancy option, keeps three copies of the data inside a single datacentre in the primary region.
- ZRS
Zone-redundant storage: data is written three times, each copy in a different availability zone of the same region, and nothing is replicated to a secondary region.
Related terms
- Autoscaling local storage
Before a node's disk fills, extra managed disks are attached to it, up to 5 TB for each virtual machine. This is on by default for every compute resource and pool.
- Azure Disk Backup
Azure Backup protection for managed disks that needs no agent, taking snapshots kept in the same region; recovery isn't orchestrated automatically.
- Backup vault
Vault type in Azure Backup aimed at newer workloads, for instance managed disks, Azure Blobs, AKS and Azure Database for PostgreSQL. Protecting Azure VMs, Azure Files or MARS backups requires a Recovery Services vault instead.
- Disk encryption set
Lets you choose your own key, held in Azure Key Vault or a Managed HSM, for the server-side encryption Azure applies to managed disks; each disk is pointed at this resource.
- Microsoft.Compute
Namespace of the resource provider that covers virtual machines, managed disks (
Microsoft.Compute/disks) and the data actions for signing in to VMs (virtualMachines/login/action). - Server-side encryption
Encryption at rest that Azure Storage always applies to managed disks, with keys managed by the platform or the customer. Caches and temp disks are excluded, and a VHD you download is unencrypted.
- Unmanaged disks
An older approach, now retired in favour of managed disks, where VM disks were VHD page blobs kept in a storage account you owned.