Encryption at rest that Azure Storage always applies to managed disks, with keys managed by the platform or the customer. Caches and temp disks are excluded, and a VHD you download is unencrypted.
Also called SSE.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Server-side encryption in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- Azure Storage
You reach this Azure data storage platform through a storage account; it covers blobs (Data Lake Storage included), file shares, queues and tables.
- Managed disks
Block storage disks for VMs whose underlying storage accounts Azure looks after. The only redundancy choices are LRS and ZRS.
- VHD
A disk image format for virtual hard disks; the Azure Migrate appliance for Hyper-V, for instance, is downloaded as one.
Related terms
- Disk encryption set
Lets you choose your own key, held in Azure Key Vault or a Managed HSM, for the server-side encryption Azure applies to managed disks; each disk is pointed at this resource.
- Security Service Edge
Delivers network security from the cloud with identity at its centre; Microsoft's offering, Global Secure Access, combines Internet Access with Private Access. Here SSE has nothing to do with server-side encryption.
- Server-Sent Events
An older streaming method for talking to remote MCP servers over HTTP. VS Code drops back to it if a server can't do streamable HTTP; the abbreviation has nothing to do with server-side encryption.