Review customer-managed keys for Managed Disk

Associate a compatible Disk Encryption Set when organizational policy requires customer-managed keys.

Description

Azure Managed Disk encrypts stored data with platform-managed keys by default. A Disk Encryption Set selects customer-managed keys; its absence does not imply plaintext storage. When separate key control is required, the organization must manage permissions, rotation and key availability.

Potential impact

  • The configuration may not meet a customer-managed-key policy.
  • Disabling a key or incorrectly revoking permissions can affect disk and VM availability.

Remediation

  • When customer-managed keys are required for an ordinary disk, set disk_encryption_set_id to an approved Disk Encryption Set.
  • For customer-key-protected Confidential VM disks, use a compatible security_type and secure_vm_disk_encryption_set_id. Do not set both ID properties together; verify Key Vault permissions, rotation and recovery procedures.

Examples

The examples compare default encryption with customer-managed-key selection for an ordinary managed disk. Prepare the Disk Encryption Set and key permissions separately.

Before

hcl
resource "azurerm_managed_disk" "example" {
  name                 = "example-disk"
  location             = azurerm_resource_group.example.location
  resource_group_name  = azurerm_resource_group.example.name
  storage_account_type = "Premium_LRS"
  create_option        = "Empty"
  disk_size_gb         = 128
}

After

hcl
resource "azurerm_managed_disk" "example" {
  name                   = "example-disk"
  location               = azurerm_resource_group.example.location
  resource_group_name    = azurerm_resource_group.example.name
  storage_account_type   = "Premium_LRS"
  create_option          = "Empty"
  disk_size_gb           = 128
  disk_encryption_set_id = azurerm_disk_encryption_set.example.id
}

Explanation:

  • Before: Default encryption uses platform-managed keys.
  • After: The disk is configured to use customer-managed keys through an approved Disk Encryption Set.

References