Cmk key change to ade enabled vms

Mohan Venkata Durgarao Y 40 Reputation points
2026-09-27T10:21:41.1766667+00:00

Hi,

Im facing an issue with Cmk key change from Pmk on the existing ade enabled or previously ade enabled vms in azure. Please help me to fix the issue. I created another disk with pmk from snapshot and fixed for OS disk. How do we fix it for data disks. What's the ideal process for fixing this issue

Azure Disk Encryption
Azure Disk Encryption

An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.

0 comments No comments

2 answers

Sort by: Newest
  1. Mohan Venkata Durgarao Y 40 Reputation points
    2026-09-28T12:46:22.7266667+00:00

    Thanks for the answer. But I'm worried what if any application installed in data disk which was ADE enabled previously

    Was this answer helpful?

    0 comments No comments

  2. Taz 10,126 Reputation points MVP Volunteer Moderator
    2026-09-27T13:53:28.3566667+00:00

    Hi Mohan,

    The issue is a documented Azure Disk Encryption limitation. A managed disk that currently has, or previously had, Azure Disk Encryption (ADE) cannot be switched directly to server-side encryption with a customer-managed key (SSE + CMK). This applies to both OS and data disks.

    For the data disks, the supported approach is to create a new managed disk without the ADE metadata, copy the data from the existing disk, and then configure the new disk with your Disk Encryption Set (DES). Microsoft specifically notes that snapshots/copies of ADE disks can retain the ADE/UDE metadata, so simply creating another disk from a snapshot is not sufficient for this migration.

    The recommended sequence is:

    Decrypt the data disk at the OS level and confirm it is fully decrypted.

    Create a new empty managed disk.

    Copy the data from the old disk to the new disk.

    Configure the new disk with your CMK/Disk Encryption Set.

    Detach the old data disk and attach the new one to the VM.

    Verify the data and application before removing the old disk.

    Also, do not rely on an ADE disk snapshot/copy for this migration, because the ADE metadata can persist. Microsoft recommends the upload/copy-data method to create a clean disk object.

    Since ADE is scheduled for retirement on September 15, 2028, Microsoft recommends moving ADE workloads to encryption at host rather than continuing to build new ADE dependencies.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.