Review Azure managed disk encryption requirements

Distinguish default server-side encryption from Azure Disk Encryption and identify any additional protection needed.

Description

Server-side encryption (SSE) is always enabled for Azure managed disks. encryptionSettingsCollection.enabled relates to the separate Azure Disk Encryption (ADE) feature. An absent or false value does not mean the stored disk data is plaintext.

Potential impact

Default SSE alone may not meet an organization's requirements for key ownership or protection of temporary disks and caches. Identify the required coverage before choosing additional controls.

Remediation

Use a disk encryption set (DES) when customer-managed keys are required, and consider encryption at host for temporary disks and caches. ADE is scheduled for retirement on September 15, 2028, so plan a supported migration for existing deployments. Changing the enabled flag alone is not an encryption operation.

Examples

Both configurations below encrypt stored data. Use the second when customer-managed keys are required. Supply the actual resource ID of a compatible DES through diskEncryptionSetId, and configure its permission to use the key.

Platform-managed key

bicep
param projectName string

var vmName = '${projectName}-vm'

resource vmName_disk1 'Microsoft.Compute/disks@2024-03-02' = {
  name: '${vmName}-disk1'
  location: resourceGroup().location
  sku: {
    name: 'Standard_LRS'
  }
  properties: {
    creationData: {
      createOption: 'Empty'
    }
    diskSizeGB: 512
    encryption: {
      type: 'EncryptionAtRestWithPlatformKey'
    }
  }
}

Customer-managed key

bicep
param projectName string
param diskEncryptionSetId string

var vmName = '${projectName}-vm'

resource vmName_disk1 'Microsoft.Compute/disks@2024-03-02' = {
  name: '${vmName}-disk1'
  location: resourceGroup().location
  sku: {
    name: 'Standard_LRS'
  }
  properties: {
    creationData: {
      createOption: 'Empty'
    }
    diskSizeGB: 512
    encryption: {
      type: 'EncryptionAtRestWithCustomerKey'
      diskEncryptionSetId: diskEncryptionSetId
    }
  }
}

References