Review Managed Disk encryption methods

Distinguish default storage encryption from additional disk-protection requirements.

Description

Data on Azure managed disks is encrypted at rest by default. Temporary-disk and cache protection and customer-managed-key requirements need separate review. Guest-based Azure Disk Encryption, customer-managed keys and encryption at host serve different purposes and use different settings.

Potential impact

  • Required protection for temporary disks, caches or key management may need additional configuration.
  • Removing existing encryption settings without planning can trigger disk replacement or interrupt data access.

Remediation

  • Check actual storage encryption and organizational key-management requirements. For additional protection on new VMs, consider supported encryption at host; configure a Disk Encryption Set when customer-managed keys are required.
  • If Azure Disk Encryption is in use, plan its documented migration to encryption at host before retirement on September 15, 2028. Review Terraform plans, backups and recovery before changing settings.

Examples

These examples compare default encryption with customer-managed-key selection. Prepare the Disk Encryption Set and key permissions separately; this property does not configure guest-based encryption or encryption at host.

Before

hcl
resource "azurerm_managed_disk" "example" {
  name                 = "acctestmd"
  location             = "West US 2"
  resource_group_name  = azurerm_resource_group.example.name
  storage_account_type = "Standard_LRS"
  create_option        = "Empty"
  disk_size_gb         = "1"

  tags = {
    environment = "staging"
  }
}

After

hcl
resource "azurerm_managed_disk" "example" {
  name                 = "acctestmd"
  location             = "West US 2"
  resource_group_name  = azurerm_resource_group.example.name
  storage_account_type = "Standard_LRS"
  create_option        = "Empty"
  disk_size_gb         = "1"

  disk_encryption_set_id = azurerm_disk_encryption_set.example.id

  tags = {
    environment = "staging"
  }
}

Explanation:

  • Before: Default encryption at rest uses platform-managed keys.
  • After: A Disk Encryption Set selects customer-managed keys. Temporary-disk and cache protection is configured separately.

References