Skip to main content
compliance · azure

Azure VMs whose OS disk relies on platform-managed keys, or with Azure Disk Encryption explicitly off

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags an Azure VM whose OS disk is encrypted only with a platform-managed key, because no disk encryption set supplies a customer-managed key, or whose Azure Disk Encryption setting is explicitly off. Server-side encryption always protects managed disks at rest, so this is a key-control finding for regimes that demand customer-held keys.

Signal and threshold

How ZopNight evaluates Azure VMs whose OS disk relies on platform-managed keys, or with Azure Disk Encryption explicitly off.
Field Value
Rule IDsRC-1300
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdno customer-managed key on the OS disk
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.Compute/disks/read

Every managed disk is encrypted; the question is whose key

Azure Disk Storage server-side encryption is always enabled. It encrypts OS and data disks at rest with a platform-managed key unless you attach a disk encryption set, which lets the key come from your own Azure Key Vault or Managed HSM. So this rule does not find unencrypted disks. It finds disks whose key lifecycle Microsoft controls rather than you.

That matters where auditors expect you to rotate, revoke and log use of the key yourself.

Seeing which key each disk uses

Terminal window
az disk list \
--query "[].{name:name, rg:resourceGroup, encryption:encryption.type}" -o table

EncryptionAtRestWithPlatformKey means a platform-managed key. EncryptionAtRestWithCustomerKey or EncryptionAtRestWithPlatformAndCustomerKeys means a disk encryption set is attached.

Two independent paths to a finding

  1. Customer-managed key check. ZopNight looks at whether the VM’s OS disk has a disk encryption set. If Azure reports that it does not, the finding fires as a platform-key gap.
  2. Azure Disk Encryption check. Used only when the key information above is not available. It fires when Azure reports the VM’s Azure Disk Encryption setting as explicitly disabled.

Only one path produces any given finding, and the finding says which one.

When nothing is raised

A VM whose OS disk has a customer-managed key is clear. A VM with no Azure Disk Encryption settings at all is not treated as unencrypted: an absent setting just means ADE was never configured, while server-side encryption still protects the disk. If neither signal is available, ZopNight stays silent.

Key-control exposure, not cost

No saving is claimed. Moving to customer-managed keys adds Key Vault operations cost and a new failure mode: if the key is disabled or deleted, the disks cannot be used.

Moving to customer-held keys

  1. Create a Key Vault key and a disk encryption set that uses it.
  2. Associate the OS disk with it, for example az disk update --resource-group my-rg --name my-osdisk --disk-encryption-set <des-id>.
  3. Confirm the disk now reports EncryptionAtRestWithCustomerKey.
  4. Do not start new Azure Disk Encryption deployments to clear the second path. Microsoft has scheduled ADE for retirement on 15 September 2028 and recommends encryption at host for new VMs; ADE-enabled VMs must migrate before that date.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·