diskEncryptionSet planning for custom CMK from managed HSM

prasantc 981 Reputation points
2025-11-05T16:33:07.55+00:00

I am working on script to replace all vm disk encryption for both Linux dm-crypt and windows bitlocker with the HSM generated key.

I wonder if it is recommended to create diskEncryptionSet per vm that way same key is not used per VM and perhaps used single key and diskEncryptionSet per VM and scalset, that way scaletset and VM disks could share same key and diskEncryptionSet.

diskEncryptionSet can only support single key. I see the potential for 2k to 3k diskEncryptionSet per subscription. Is it a normal approach for diskEncryptionSet?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.