Description
Azure Managed Disk encrypts stored data with platform-managed keys by default. A Disk Encryption Set selects customer-managed keys; its absence does not imply plaintext storage. When separate key control is required, the organization must manage permissions, rotation and key availability.
Potential impact
- The configuration may not meet a customer-managed-key policy.
- Disabling a key or incorrectly revoking permissions can affect disk and VM availability.
Remediation
- When customer-managed keys are required for an ordinary disk, set
disk_encryption_set_idto an approved Disk Encryption Set. - For customer-key-protected Confidential VM disks, use a compatible
security_typeandsecure_vm_disk_encryption_set_id. Do not set both ID properties together; verify Key Vault permissions, rotation and recovery procedures.
Examples
The examples compare default encryption with customer-managed-key selection for an ordinary managed disk. Prepare the Disk Encryption Set and key permissions separately.
Before
hcl
resource "azurerm_managed_disk" "example" {
name = "example-disk"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
storage_account_type = "Premium_LRS"
create_option = "Empty"
disk_size_gb = 128
}
After
hcl
resource "azurerm_managed_disk" "example" {
name = "example-disk"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
storage_account_type = "Premium_LRS"
create_option = "Empty"
disk_size_gb = 128
disk_encryption_set_id = azurerm_disk_encryption_set.example.id
}
Explanation:
- Before: Default encryption uses platform-managed keys.
- After: The disk is configured to use customer-managed keys through an approved Disk Encryption Set.