Not able to encrypt for OS disk in the VM

sns 9,226 Reputation points
2022-12-31T11:53:09.033+00:00

I have navigated to VM--> Disks--> Additional settings --> I have chosen OS disk and also chosen respective Key vault and key--> after saving it is giving below error. Please suggest
275193-image.png

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,531 Reputation points Microsoft Employee
    2023-01-04T20:40:30.313+00:00

    @sns
    Thank you for your post!

    Error Message:
    Disk encryption set resource cannot be added to VM having disks that were encrypted with Azure Disk Encryption. For more information, see https://aka.ms/ssecmkrestrictions

    I understand that you're trying to leverage Azure Disk Encryption to encrypt your OS disk but are running into the above error message after modifying your disks' encryption settings within your VM. From your error message, can you share some more info so I can gain a better understanding of your issue?

    • Was your VM previously encrypted with Azure Disk Encryption?
    • Is the OS disk you're trying to encrypt currently with SSE with PMK or CMK?
    • Can you share a screenshot of your VM's Disk blade?

    276281-image.png
    Please keep in mind that, applying ADE to a VM that has disks encrypted with Encryption at Host, server-side encryption with customer-managed keys (SSE + CMK); applying SSE + CMK to a data disk, or adding a data disk with SSE + CMK configured to a VM encrypted with ADE is an unsupported scenario. For more info - ADE Unsupported scenarios.

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.


1 additional answer

Sort by: Most helpful
  1. JimmySalian-2011 42,071 Reputation points
    2022-12-31T12:24:57.98+00:00

    Hi,

    It seems there is a conflict with some resource, please check the troubleshooting steps and also paste the deployment json file for detailed plan review.
    disk-encryption-troubleshooting

    If it is Linux VM check this page - disk-encryption-troubleshooting

    Hope this helps.
    JS

    ==
    Please Accept the answer if the information helped you. This will help us and others in the community as well.