Azure VMs whose OS disk relies on platform-managed keys, or with Azure Disk Encryption explicitly off
What does ZopNight detect here?
ZopNight flags an Azure VM whose OS disk is encrypted only with a platform-managed key, because no disk encryption set supplies a customer-managed key, or whose Azure Disk Encryption setting is explicitly off. Server-side encryption always protects managed disks at rest, so this is a key-control finding for regimes that demand customer-held keys.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1300 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | no customer-managed key on the OS disk |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Compute/disks/read |
Where it applies
Every managed disk is encrypted; the question is whose key
Azure Disk Storage server-side encryption is always enabled. It encrypts OS and data disks at rest with a platform-managed key unless you attach a disk encryption set, which lets the key come from your own Azure Key Vault or Managed HSM. So this rule does not find unencrypted disks. It finds disks whose key lifecycle Microsoft controls rather than you.
That matters where auditors expect you to rotate, revoke and log use of the key yourself.
Seeing which key each disk uses
az disk list \ --query "[].{name:name, rg:resourceGroup, encryption:encryption.type}" -o tableEncryptionAtRestWithPlatformKey means a platform-managed key.
EncryptionAtRestWithCustomerKey or EncryptionAtRestWithPlatformAndCustomerKeys means a disk
encryption set is attached.
Two independent paths to a finding
- Customer-managed key check. ZopNight looks at whether the VM’s OS disk has a disk encryption set. If Azure reports that it does not, the finding fires as a platform-key gap.
- Azure Disk Encryption check. Used only when the key information above is not available. It fires when Azure reports the VM’s Azure Disk Encryption setting as explicitly disabled.
Only one path produces any given finding, and the finding says which one.
When nothing is raised
A VM whose OS disk has a customer-managed key is clear. A VM with no Azure Disk Encryption settings at all is not treated as unencrypted: an absent setting just means ADE was never configured, while server-side encryption still protects the disk. If neither signal is available, ZopNight stays silent.
Key-control exposure, not cost
No saving is claimed. Moving to customer-managed keys adds Key Vault operations cost and a new failure mode: if the key is disabled or deleted, the disks cannot be used.
Moving to customer-held keys
- Create a Key Vault key and a disk encryption set that uses it.
- Associate the OS disk with it, for example
az disk update --resource-group my-rg --name my-osdisk --disk-encryption-set <des-id>. - Confirm the disk now reports
EncryptionAtRestWithCustomerKey. - Do not start new Azure Disk Encryption deployments to clear the second path. Microsoft has scheduled ADE for retirement on 15 September 2028 and recommends encryption at host for new VMs; ADE-enabled VMs must migrate before that date.