PMK / CMK keys

Az Student 1 Reputation point
2022-12-06T18:01:33.827+00:00

I know when you create a CMK for vm encryption you create a KV that a DES policy will pull from. Thus, if I spin up / deploy 1,000 vm's that a particular DES, all 1,000 will have they same encryption key. I know you can create multiple KV/DES policies with different CMKs, etc.. But my questions is how are PMK handled in this scenario? For example, if I spin up / deploy 1,000 vm's just using the default SSE/PMK do all 1,000 get the same PMK or is there some algorithm that generates a unique key for each vm, for each set of 10 vm's, etc???

Thanks in advance

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,216 Reputation points
    2022-12-08T00:00:39.753+00:00

    @Az Student Thank you for reaching out to Microsoft Q&A. I understand that you are having questions regarding PMK and if it can be used for multiple VMs.

    It is possible that disks in the same subscription can share the same PMK. However, we don't share PMKs between different subscriptions unless you move the disks to another subscription yourself. Hope this answers your question.

    Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.