Enable double encryption at rest for managed disks

Applies to: ✔️ Linux VMs ✔️ Windows VMs ✔️

Azure Disk Storage supports double encryption at rest for managed disks. For conceptual information on double encryption at rest, and other managed disk encryption types, see the Double encryption at rest section of our disk encryption article.

Restrictions

Double encryption at rest isn't currently supported with either Ultra Disks or Premium SSD v2 disks.

Prerequisites

If you're going to use Azure CLI, install the latest Azure CLI and sign in to an Azure account with az login.

If you're going to use Azure PowerShell, install the latest Azure PowerShell version, and sign in to an Azure account by using Connect-AzAccount.

If you create a key vault, enable soft delete and purge protection. Soft delete retains a deleted key for the retention period, which is 90 days by default. Purge protection prevents permanent deletion until that period ends. Both settings are mandatory when you use Azure Key Vault to encrypt managed disks.

Enable double encryption at rest

Enable double encryption in the Azure portal

  1. Sign in to the Azure portal.

  2. Search for and select Disk Encryption Sets.

    Screenshot of the Azure portal search results with Disk Encryption Sets highlighted.

  3. Select + Create.

  4. Select one of the supported regions.

  5. For Encryption type, select Double encryption with platform-managed and customer-managed keys.

    Note

    Once you create a disk encryption set with a particular encryption type, it cannot be changed. If you want to use a different encryption type, you must create a new disk encryption set.

  6. Fill in the remaining info.

    Screenshot of disk encryption set creation with China North 2 selected and Double encryption with platform-managed and customer-managed keys selected.

  7. Select an Azure Key Vault and key, or create a new one if necessary.

    Note

    If you create a key vault, enable soft delete and purge protection as described in the prerequisites.

    Screenshot of the Select key from Azure Key Vault pane with a key vault and key selected.

  8. Select Create.

  9. Navigate to the disk encryption set you created, and then select the alert to grant the required key vault permissions.

    Screenshot of an alert that requires granting the disk encryption set permission to the selected key vault.

    The notifications confirm that the role was assigned and the key vault permissions were granted.

    Screenshot of notifications confirming that the role was assigned and key vault permissions were granted.

  10. Navigate to your disk.

  11. Select Encryption.

  12. For Encryption type, select Double encryption with platform-managed and customer-managed keys.

  13. Select your disk encryption set.

  14. select Save.

You have now enabled double encryption at rest on your managed disk.

Next steps