An Azure service that provides cloud-scale job scheduling and compute management.
Hello Daniel-4204
Your diskEncryptionConfiguration: {} does not mean that ADE is enabled. It means you haven't configured the Batch disk-encryption targets through that property. The disks are still encrypted at rest by Azure's default storage encryption. diskEncryptionConfiguration.targets represents configuration intent, not a reliable indication of the actual encryption mechanism used underneath. (Microsoft Learn)
Recommendation itself is published against the Batch account and says to migrate Batch pools to VMs that support Encryption at Host; Microsoft does not publish the exact detection logic. So proof that your existing nodes are running ADE. (Microsoft Learn)
For your case, I would do this:
- Check whether the current SKU supports Encryption at Host. Microsoft exposes the VM capability
EncryptionAtHostSupported=True. Do not assumeD2s_v3orD2s_v5support based only on the family name; verify the specific SKU/region. (Microsoft Learn) - If you are changing the pool anyway, moving off
Standard_D2s_v3now is sensible. Dv3/Dsv3 retire on 15 November 2029. Microsoft recommends v5 for the smoothest migration, while v6/v7 are the more current generations. (Microsoft Learn) - You probably do not need to delete/recreate the pool. The current Batch Service API allows both
vmSizeandvirtualMachineConfigurationto be changed when the pool has zero compute nodes.securityProfile.encryptionAtHostis part of that configuration. (Microsoft Learn)
So the preferred remediation is:
Drain jobs → scale pool to 0 → update vmSize + set securityProfile.encryptionAtHost=true → scale back up → validate.
Use the existing VM configuration when patching; the Batch API requires virtualMachineConfiguration for this update. This lets you keep the same pool ID, so reports and downstream references do not need to change. (Microsoft Learn)
For Microsoft.Compute/EncryptionAtHost registration: I would not register it pre-emptively for a Batch service-mode pool. Generic VM documentation requires registration in the subscription that owns the VM/VMSS, while Batch service allocation uses Batch-managed compute. If Batch returns an explicit feature-registration error, follow that error; otherwise it is not a documented prerequisite.
Finally, after reprovisioning the nodes with Encryption at Host, wait for the next Advisor refresh. If the recommendation still remains, open an Azure Support case and reference the Advisor recommendation ID 6c4cd580-41fb-4f20-977b-3be3cbead46e, because at that point the issue may be Advisor detection rather than the pool configuration. (Microsoft Learn)