Review Azure VM encryption at host

Check required temporary-disk and cache protection in addition to default disk encryption.

Description

Encryption at host protects disk data handled on the VM host, including temporary disks and disk caches. Disabling it does not remove default encryption at rest for managed disks. Check the VM size’s built-in protection and any additional organizational requirements.

Potential impact

  • Required temporary-disk and cache protections may not be met.
  • Changing encryption methods without checking compatibility can disrupt deployment or operation.

Remediation

  • Verify that the VM size in the region and the subscription support encryption at host before considering encryption_at_host_enabled = true. For VMs that use or previously used Azure Disk Encryption, follow the documented compatibility and migration requirements.
  • Plan any required deallocation and reallocation for existing VMs and verify the result. Changing a VM scale-set setting alone does not apply it to every existing instance; check each instance’s state.

Examples

These VM scale-set excerpts compare only encryption at host. Adjust the example SKU to a size supported in the region and subscription, and provide omitted OS-disk, image and networking settings.

Before

hcl
resource "azurerm_windows_virtual_machine_scale_set" "example" {
  name                 = "example-vmss"
  resource_group_name  = azurerm_resource_group.example.name
  location             = azurerm_resource_group.example.location
  sku                  = "Standard_F2"
  instances            = 2
  admin_username       = var.admin_username
  admin_password       = var.admin_password
  computer_name_prefix = "example"

  encryption_at_host_enabled = false
}

After

hcl
resource "azurerm_windows_virtual_machine_scale_set" "example" {
  name                 = "example-vmss"
  resource_group_name  = azurerm_resource_group.example.name
  location             = azurerm_resource_group.example.location
  sku                  = "Standard_F2"
  instances            = 2
  admin_username       = var.admin_username
  admin_password       = var.admin_password
  computer_name_prefix = "example"

  encryption_at_host_enabled = true
}

Explanation:

  • Before: Encryption at host is disabled. This is separate from default managed-disk encryption at rest.
  • After: Encryption at host is requested. Verify support requirements and its actual application to existing instances.

References