Proposed Pull Request Change

title description author ms.date ms.topic ms.author ms.service ms.custom
Azure CLI - Enable customer-managed keys with SSE - managed disks Enable customer-managed keys on your managed disks with the Azure CLI. roygara 05/03/2023 how-to rogarana azure-disk-storage devx-track-azurecli, linux-related-content
📄 Document Links
GitHub View on GitHub Microsoft Learn View on Microsoft Learn
⚠ Content Truncation Detected
The generated rewrite appears to be incomplete.
Original lines: -
Output lines: -
Ratio: -
Raw New Markdown
Generating updated version of doc...
Rendered New Markdown
Generating updated version of doc...
+0 -0
+0 -0
--- title: Azure CLI - Enable customer-managed keys with SSE - managed disks description: Enable customer-managed keys on your managed disks with the Azure CLI. author: roygara ms.date: 05/03/2023 ms.topic: how-to ms.author: rogarana ms.service: azure-disk-storage ms.custom: devx-track-azurecli, linux-related-content # Customer intent: As an IT administrator, I want to enable server-side encryption with customer-managed keys on managed disks using the command-line interface, so that I can ensure data security and compliance within my organization's cloud infrastructure. --- # Use the Azure CLI to enable server-side encryption with customer-managed keys for managed disks **Applies to:** :heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs :heavy_check_mark: Flexible scale sets :heavy_check_mark: Uniform scale sets Azure Disk Storage allows you to manage your own keys when using server-side encryption (SSE) for managed disks, if you choose. For conceptual information on SSE with customer managed keys, as well as other managed disk encryption types, see the [Customer-managed keys](../disk-encryption.md#customer-managed-keys) section of our disk encryption article. ## Restrictions For now, customer-managed keys have the following restrictions: [!INCLUDE [virtual-machines-managed-disks-customer-managed-keys-restrictions](../includes/virtual-machines-managed-disks-customer-managed-keys-restrictions.md)] ## Create resources Once the feature is enabled, you'll need to set up a DiskEncryptionSet and either an [Azure Key Vault](/azure/key-vault/general/overview) or an [Azure Key Vault Managed HSM](/azure/key-vault/managed-hsm/overview). [!INCLUDE [virtual-machines-disks-encryption-create-key-vault](../includes/virtual-machines-disks-encryption-create-key-vault-cli.md)] Now that you've created and configured these resources, you can use them to secure your managed disks. The following links contain example scripts, each with a respective scenario, that you can use to secure your managed disks. ## Examples ### Create a VM using a Marketplace image, encrypting the OS and data disks with customer-managed keys ```azurecli rgName=yourResourceGroupName vmName=yourVMName location=westcentralus vmSize=Standard_DS3_V2 image=LinuxImageURN diskEncryptionSetName=yourDiskencryptionSetName diskEncryptionSetId=$(az disk-encryption-set show -n $diskEncryptionSetName -g $rgName --query [id] -o tsv) az vm create -g $rgName -n $vmName -l $location --image $image --size $vmSize --generate-ssh-keys --os-disk-encryption-set $diskEncryptionSetId --data-disk-sizes-gb 128 128 --data-disk-encryption-sets $diskEncryptionSetId $diskEncryptionSetId ``` ### Encrypt existing managed disks Your existing disks must not be attached to a running VM in order for you to encrypt them using the following script: ```azurecli rgName=yourResourceGroupName diskName=yourDiskName diskEncryptionSetName=yourDiskEncryptionSetName diskEncryptionSetId=$(az disk-encryption-set show -n $diskEncryptionSetName -g $rgName --query [id] -o tsv) az disk update -n $diskName -g $rgName --encryption-type EncryptionAtRestWithCustomerKey --disk-encryption-set $diskEncryptionSetId ``` ### Create a virtual machine scale set using a Marketplace image, encrypting the OS and data disks with customer-managed keys ```azurecli rgName=yourResourceGroupName vmssName=yourVMSSName location=westcentralus vmSize=Standard_DS3_V2 image=LinuxImageURN diskEncryptionSetName=yourDiskencryptionSetName diskEncryptionSetId=$(az disk-encryption-set show -n $diskEncryptionSetName -g $rgName --query [id] -o tsv) az vmss create -g $rgName -n $vmssName --image $image --upgrade-policy automatic --admin-username azureuser --generate-ssh-keys --os-disk-encryption-set $diskEncryptionSetId --data-disk-sizes-gb 64 128 --data-disk-encryption-sets $diskEncryptionSetId $diskEncryptionSetId ``` ### Create an empty disk encrypted using server-side encryption with customer-managed keys and attach it to a VM ```azurecli vmName=yourVMName rgName=yourResourceGroupName diskName=yourDiskName diskSkuName=Premium_LRS diskSizeinGiB=30 location=westcentralus diskLUN=2 diskEncryptionSetName=yourDiskEncryptionSetName diskEncryptionSetId=$(az disk-encryption-set show -n $diskEncryptionSetName -g $rgName --query [id] -o tsv) az disk create -n $diskName -g $rgName -l $location --encryption-type EncryptionAtRestWithCustomerKey --disk-encryption-set $diskEncryptionSetId --size-gb $diskSizeinGiB --sku $diskSkuName diskId=$(az disk show -n $diskName -g $rgName --query [id] -o tsv) az vm disk attach --vm-name $vmName --lun $diskLUN --ids $diskId ``` ### Change the key of a DiskEncryptionSet to rotate the key for all the resources referencing the DiskEncryptionSet ```azurecli rgName=yourResourceGroupName keyVaultName=yourKeyVaultName keyName=yourKeyName diskEncryptionSetName=yourDiskEncryptionSetName keyVaultId=$(az keyvault show --name $keyVaultName--query [id] -o tsv) keyVaultKeyUrl=$(az keyvault key show --vault-name $keyVaultName --name $keyName --query [key.kid] -o tsv) az disk-encryption-set update -n keyrotationdes -g keyrotationtesting --key-url $keyVaultKeyUrl --source-vault $keyVaultId ``` ### Find the status of server-side encryption of a disk [!INCLUDE [virtual-machines-disks-encryption-status-cli](../includes/virtual-machines-disks-encryption-status-cli.md)] > [!IMPORTANT] > Customer-managed keys rely on managed identities for Azure resources, a feature of Microsoft Entra ID. When you configure customer-managed keys, a managed identity is automatically assigned to your resources under the covers. If you subsequently move the subscription, resource group, or managed disk from one Microsoft Entra directory to another, the managed identity associated with the managed disks is not transferred to the new tenant, so customer-managed keys may no longer work. For more information, see [Transferring a subscription between Microsoft Entra directories](/azure/active-directory/managed-identities-azure-resources/known-issues#transferring-a-subscription-between-azure-ad-directories). ## Next steps - [Explore the Azure Resource Manager templates for creating encrypted disks with customer-managed keys](https://github.com/ramankumarlive/manageddiskscmkpreview) - [Replicate machines with customer-managed keys enabled disks](/azure/site-recovery/azure-to-azure-how-to-enable-replication-cmk-disks) - [Set up disaster recovery of VMware VMs to Azure with PowerShell](/azure/site-recovery/vmware-azure-disaster-recovery-powershell#replicate-vmware-vms) - [Set up disaster recovery to Azure for Hyper-V VMs using PowerShell and Azure Resource Manager](/azure/site-recovery/hyper-v-azure-powershell-resource-manager#step-7-enable-vm-protection) - See [Create a managed disk from a snapshot with CLI](../scripts/create-managed-disk-from-snapshot.md#disks-with-customer-managed-keys) for a code sample.
Success! Branch created successfully. Create Pull Request on GitHub
Error: