Description
Encryption at host protects disk data handled on the VM host, including temporary disks and disk caches. Disabling it does not remove default encryption at rest for managed disks. Check the VM size’s built-in protection and any additional organizational requirements.
Potential impact
- Required temporary-disk and cache protections may not be met.
- Changing encryption methods without checking compatibility can disrupt deployment or operation.
Remediation
- Verify that the VM size in the region and the subscription support encryption at host before considering
encryption_at_host_enabled = true. For VMs that use or previously used Azure Disk Encryption, follow the documented compatibility and migration requirements. - Plan any required deallocation and reallocation for existing VMs and verify the result. Changing a VM scale-set setting alone does not apply it to every existing instance; check each instance’s state.
Examples
These VM scale-set excerpts compare only encryption at host. Adjust the example SKU to a size supported in the region and subscription, and provide omitted OS-disk, image and networking settings.
Before
hcl
resource "azurerm_windows_virtual_machine_scale_set" "example" {
name = "example-vmss"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
sku = "Standard_F2"
instances = 2
admin_username = var.admin_username
admin_password = var.admin_password
computer_name_prefix = "example"
encryption_at_host_enabled = false
}
After
hcl
resource "azurerm_windows_virtual_machine_scale_set" "example" {
name = "example-vmss"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
sku = "Standard_F2"
instances = 2
admin_username = var.admin_username
admin_password = var.admin_password
computer_name_prefix = "example"
encryption_at_host_enabled = true
}
Explanation:
- Before: Encryption at host is disabled. This is separate from default managed-disk encryption at rest.
- After: Encryption at host is requested. Verify support requirements and its actual application to existing instances.