Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Azure offers three distinct ways to protect VM disks: Azure Disk Encryption (ADE) encrypts volumes inside the guest OS, managed-disk customer-managed keys (CMK) protect disk encryption keys through a Disk Encryption Set, and encryption at host protects data at the VM host layer. For an existing Windows VM that specifically needs guest-OS encryption, use ADE through the VM’s disk settings or Azure CLI. Microsoft recommends encryption at host for new VMs, and ADE is scheduled to retire on September 15, 2028.

Choose the Azure encryption method first

Choose the method that matches your security requirement rather than treating every Key Vault option as Azure VM disk encryption.

Method Where encryption occurs Key Vault object Best fit
Azure Disk Encryption Inside Windows or Linux Secrets and encryption keys Existing workloads that specifically require guest-OS encryption
Managed-disk CMK Azure Storage service RSA key and Disk Encryption Set Customer-controlled keys for managed disks
Encryption at host VM host, including caches and temporary disks Disk Encryption Set, optionally backed by a CMK New VMs and workloads that need broader host-level protection

The Encryption Type field in the VM creation wizard configures managed-disk encryption, not ADE. To use ADE, deploy the VM and then open VM → Disks → Additional settings.

Requirements for Azure Disk Encryption

Before enabling ADE, check the following:

  • The Key Vault must be in the same Azure region, subscription, and Microsoft Entra tenant as the VM.
  • The Key Vault must have soft delete enabled. Newly created vaults normally have it enabled by default.
  • The vault must be enabled for disk encryption. In the portal, use the Azure Disk Encryption for volume encryption access-policy option.
  • The VM must be able to reach the Azure storage endpoint hosting the VM extension repository and the storage account hosting its VHD files.
  • On Windows, incompatible BitLocker Group Policy settings can prevent ADE from completing. Examples include enforced TPM protectors, blocking AES-CBC, incompatible recovery-key settings, or MBAM features.

ADE supports Windows and Linux, but the current portal quickstart and the procedure below use a Windows VM. Linux deployments generally use the ADE CLI or PowerShell workflow and DM-Crypt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Encrypt an existing Windows VM with ADE in the Azure portal

The operation changes the VM’s disk encryption configuration and requires a reboot. Plan a maintenance window before saving the setting.

  1. Sign in to the Azure portal and open the virtual machine.
  2. In the VM’s left navigation, select Disks.
  3. On the top bar, select Additional settings.
  4. Under Encryption settings, set Disks to encrypt to OS and data disks. Choose OS disk instead if data disks should remain unencrypted by ADE.
  5. Select Select a key vault and key for encryption.
  6. On Select key from Azure Key Vault, select Create new.
  7. To the left of Key vault and key, select Click to select a key.
  8. On the next Select key from Azure Key Vault page, under Key Vault, select Create new.
  9. On Create key vault, choose the resource group and enter a globally unique vault name. Keep the vault in the VM’s region, subscription, and Microsoft Entra tenant.
  10. Open the Access policies tab and select Azure Disk Encryption for volume encryption.
  11. Select Review + create. After validation succeeds, select Create.
  12. Back on the key-selection page, leave Key blank and select Select. ADE creates and manages the required key material in the vault.
  13. Select Save on the encryption page.
  14. When the reboot warning appears, select Yes.

Wait for the operation and VM extension to finish before assuming the disk is protected. The first reboot is part of the encryption workflow, not an optional restart.

Verify ADE encryption in the portal

Return to the VM’s Disks → Additional settings page and check the encryption status. You can also inspect the VM’s extensions for the Azure Disk Encryption extension and review the deployment or activity log if the operation failed.

Do not use BitLocker directly inside Windows to decrypt a VM that was encrypted through ADE. Microsoft warns that doing so can cause data loss. Use the Azure Disk Encryption workflow when changing or removing ADE.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encrypt the VM with Azure CLI

The current CLI workflow does not require the older Microsoft Entra ID or service-principal arguments for normal az vm encryption use.

  1. Sign in and, if necessary, select the correct subscription:

az login

az account set --subscription "<your-subscription-id>"

  1. Create a resource group if necessary:

az group create --name "myResourceGroup" --location eastus

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Create a Key Vault enabled for disk encryption:

az keyvault create --name "<your-unique-keyvault-name>" --resource-group "myResourceGroup" --location "eastus" --enabled-for-disk-encryption

  1. Enable ADE on the VM:

az vm encryption enable -g MyResourceGroup --name MyVM --disk-encryption-keyvault myKV

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To encrypt only the VM’s data disks, add --volume-type DATA:

az vm encryption enable --disk-encryption-keyvault MyVault --name MyVm --resource-group MyResourceGroup --volume-type DATA

  1. Check the resulting status:

az vm encryption show --name MyVM -g MyResourceGroup

The Key Vault used by ADE must be in the same region, subscription, and Microsoft Entra tenant as the VM. If the vault already exists, update it instead of creating another one:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

az keyvault update --name "<your-unique-keyvault-name>" --resource-group "MyResourceGroup" --enabled-for-disk-encryption "true"

Optional deployment permissions are separate settings. Add --enabled-for-deployment "true" for Azure VM deployment access or --enabled-for-template-deployment "true" for ARM template deployment access only when your deployment design requires them.

Use encryption at host for a new VM

For a new VM, encryption at host is generally the more appropriate current option. It encrypts OS and data disk caches, temporary disks, and ephemeral OS disks at the host layer. With a customer-managed key, OS and data disk caches use the CMK; temporary disks and ephemeral OS disks use platform-managed keys.

Register the feature before deploying:

az account set --subscription "<your-subscription-id>"

az feature register --name EncryptionAtHost --namespace Microsoft.Compute

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

az feature show --name EncryptionAtHost --namespace Microsoft.Compute

Wait until the registration state is Registered. Registration can take several minutes.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Create a CMK-backed Disk Encryption Set

  1. In the portal, search for Key Vaults and select +Create.
  2. Enable soft delete and purge protection. These settings are mandatory for a Key Vault used with managed-disk CMK. The documented default soft-delete retention is 90 days.
  3. Open the vault and select Objects → Keys → Generate/Import.
  4. Create or import an RSA key. Supported RSA sizes are 2048, 3072, and 4096 bits; 2048 bits is the documented default.
  5. Open Access control (IAM), select Add role assignment, and grant the documented access role—Key Vault Administrator, Owner, or Contributor—as appropriate for your environment.
  6. Search for Disk Encryption Sets and select +Create.
  7. Choose the resource group and region. For Encryption type, select Encryption at-rest with a customer-managed key.
  8. Keep Select Azure key vault and key selected, then choose the vault, key, and key version. Enable automatic key rotation if it fits your key-management policy.
  9. Select Review + Create, then Create.
  10. Open the Disk Encryption Set and select the alert that grants it access to the Key Vault.
  11. During VM creation, open the Disks pane, select Encryption at host, choose Key management, and select the customer-managed key.

A Disk Encryption Set’s encryption type cannot be changed after creation. If you choose the wrong type, create a new Disk Encryption Set. A Key Vault CMK protects the disk’s data-encryption key; it does not directly encrypt every block of VM data with RSA.

Apply managed-disk CMK encryption to an existing VM

For an existing managed disk, the portal workflow requires the VM to be stopped:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open the VM and select Stop. Wait until it is fully stopped and deallocated.
  2. Select Disks.
  3. Select the OS or data disk.
  4. Select Encryption.
  5. Under Key management, select the Key Vault and key under Customer-managed key.
  6. Select Save.
  7. Repeat the process for each attached disk that needs the CMK.
  8. Start the VM after every required disk has finished switching.

Important limitations before changing encryption

  • ADE and encryption at host cannot be combined. Encryption at host cannot be enabled on a VM or scale set that currently has or previously had ADE enabled. ADE also cannot be enabled on disks with encryption at host enabled.
  • ADE and managed-disk CMK are also incompatible for the same disk. A disk currently or previously protected by ADE cannot be moved directly to the managed-disk CMK path.
  • Existing encryption-at-host VMs need reallocation. For scale sets, the feature affects instances created afterward; existing instances must be deallocated and reallocated.
  • Keep locations aligned. For encryption at host, the Disk Encryption Set, VM, disks, and snapshots must be in the same region and subscription. The Key Vault can be in another subscription, but must be in the Disk Encryption Set’s region.
  • Protect the key continuously. Disabling, deleting, or allowing the CMK to expire can cause disk I/O to fail after roughly one hour. VMs using the key may shut down automatically and will not boot until the key is restored or replaced.
  • Plan tenant moves carefully. Moving a subscription, resource group, or managed disk between Microsoft Entra tenants does not transfer the managed identity associated with the disk.
  • Watch incremental snapshots. If a CMK-protected disk has incremental snapshots, CMK cannot be disabled on that disk or its snapshots. The documented workaround is to copy the data to another managed disk that does not use CMK. A disk and its incremental snapshots must use the same Disk Encryption Set.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot ADE failures

If ADE fails on Windows, start with the VM extension status and the Key Vault access configuration. Then check these common causes:

  • The vault is in the wrong region, subscription, or tenant.
  • The vault was not created or updated with enabled-for-disk-encryption.
  • Outbound firewall rules block the VM’s access to the extension repository or VHD storage endpoint.
  • Domain Group Policy enforces TPM protectors, blocks the required AES-CBC algorithm, requires an unsupported recovery-key policy, or enables incompatible MBAM settings.
  • The VM has a machine-account-lockout security setting. ADE does not store recovery keys; recovery may require supplying a recovery key through the VM serial console.

For a production VM, take a tested backup and confirm that you can recover the workload before changing encryption. ADE is scheduled to retire on September 15, 2028. Microsoft states that after that date ADE-enabled VMs may keep running until reboot, but encrypted disks will fail to unlock after reboot; migrate ADE-enabled VMs and backups before retirement. New designs should normally use encryption at host or managed-disk CMK instead.

References: Azure Disk Encryption overview, ADE portal quickstart, ADE CLI quickstart, and Encryption at host in the portal.

FAQ

Does Azure Key Vault encrypt an Azure VM disk directly?

Not in the usual CMK design. Managed disks use envelope encryption: an AES-256 data-encryption key encrypts the disk data, while the RSA key in Key Vault protects that data-encryption key. ADE is different because it uses BitLocker or DM-Crypt inside the guest OS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Can I enable ADE from the VM creation wizard?

No. The VM wizard’s Encryption Type field is for managed-disk encryption and customer-managed keys. Deploy the VM first, then use VM → Disks → Additional settings for ADE.

Is Azure Disk Encryption still recommended for new VMs?

No. Microsoft recommends encryption at host for new VMs. ADE is scheduled for retirement on September 15, 2028; migrate ADE-enabled VMs and backups before that date because encrypted disks will fail to unlock after a VM reboot following retirement.

Can I use one Key Vault for ADE and managed-disk CMK?

The encryption methods have different Key Vault requirements. ADE requires the vault and VM to be in the same region, subscription, and Microsoft Entra tenant. Managed-disk CMK uses an RSA key and Disk Encryption Set, with soft delete and purge protection enabled. Plan the vault and permissions for the method you are deploying.

What happens if the customer-managed key is disabled or deleted?

Disk I/O generally starts failing after about one hour. A VM using the key can be shut down automatically and will not boot until the key is re-enabled or replaced. Do not treat Key Vault key rotation, expiration, or deletion as a harmless administrative change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I enable encryption at host on a VM that previously used ADE?

No. ADE and encryption at host are mutually exclusive, including for a VM that previously had ADE enabled. A direct switch is not supported; use the documented migration approach for the workload.

The Bottom Line

For guest-OS encryption on an existing VM, configure ADE through VM → Disks → Additional settings or az vm encryption enable, using a Key Vault enabled for disk encryption. Do not confuse that process with the VM wizard’s Encryption Type field. For new deployments, prefer encryption at host, optionally backed by a customer-managed RSA key through a Disk Encryption Set. ADE retires on September 15, 2028; migrate ADE-enabled VMs and backups before then to avoid disks failing to unlock after reboot.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.