Hi Mohan,
The issue is a documented Azure Disk Encryption limitation. A managed disk that currently has, or previously had, Azure Disk Encryption (ADE) cannot be switched directly to server-side encryption with a customer-managed key (SSE + CMK). This applies to both OS and data disks.
For the data disks, the supported approach is to create a new managed disk without the ADE metadata, copy the data from the existing disk, and then configure the new disk with your Disk Encryption Set (DES). Microsoft specifically notes that snapshots/copies of ADE disks can retain the ADE/UDE metadata, so simply creating another disk from a snapshot is not sufficient for this migration.
The recommended sequence is:
Decrypt the data disk at the OS level and confirm it is fully decrypted.
Create a new empty managed disk.
Copy the data from the old disk to the new disk.
Configure the new disk with your CMK/Disk Encryption Set.
Detach the old data disk and attach the new one to the VM.
Verify the data and application before removing the old disk.
Also, do not rely on an ADE disk snapshot/copy for this migration, because the ADE metadata can persist. Microsoft recommends the upload/copy-data method to create a clean disk object.
Since ADE is scheduled for retirement on September 15, 2028, Microsoft recommends moving ADE workloads to encryption at host rather than continuing to build new ADE dependencies.