Description
Data on Azure managed disks is encrypted at rest by default. Temporary-disk and cache protection and customer-managed-key requirements need separate review. Guest-based Azure Disk Encryption, customer-managed keys and encryption at host serve different purposes and use different settings.
Potential impact
- Required protection for temporary disks, caches or key management may need additional configuration.
- Removing existing encryption settings without planning can trigger disk replacement or interrupt data access.
Remediation
- Check actual storage encryption and organizational key-management requirements. For additional protection on new VMs, consider supported encryption at host; configure a Disk Encryption Set when customer-managed keys are required.
- If Azure Disk Encryption is in use, plan its documented migration to encryption at host before retirement on September 15, 2028. Review Terraform plans, backups and recovery before changing settings.
Examples
These examples compare default encryption with customer-managed-key selection. Prepare the Disk Encryption Set and key permissions separately; this property does not configure guest-based encryption or encryption at host.
Before
hcl
resource "azurerm_managed_disk" "example" {
name = "acctestmd"
location = "West US 2"
resource_group_name = azurerm_resource_group.example.name
storage_account_type = "Standard_LRS"
create_option = "Empty"
disk_size_gb = "1"
tags = {
environment = "staging"
}
}
After
hcl
resource "azurerm_managed_disk" "example" {
name = "acctestmd"
location = "West US 2"
resource_group_name = azurerm_resource_group.example.name
storage_account_type = "Standard_LRS"
create_option = "Empty"
disk_size_gb = "1"
disk_encryption_set_id = azurerm_disk_encryption_set.example.id
tags = {
environment = "staging"
}
}
Explanation:
- Before: Default encryption at rest uses platform-managed keys.
- After: A Disk Encryption Set selects customer-managed keys. Temporary-disk and cache protection is configured separately.