Un servizio di Azure usato per effettuare il provisioning di macchine virtuali Windows e Linux.
Hello Passion,
Thank you for reaching out Q/A.
If your Azure VMs are using Managed Disks, Azure already encrypts OS and data disks at rest by default using Server-Side Encryption (SSE) with platform-managed keys. Therefore, not enabling Encryption at Host or Double Encryption does not mean your disks are unencrypted.
The primary difference is the scope of protection:
- Server-Side Encryption (default) protects managed disks stored in Azure Storage.
- Encryption at Host extends encryption to the VM host layer and also covers temporary disks, caches, and data flowing between the VM host and Azure Storage.
- Double Encryption adds an additional encryption layer and is typically implemented for defense-in-depth or regulatory/compliance requirements.
From a practical security perspective, the absence of Encryption at Host or Double Encryption is usually not a direct attack vector related to internet exposure. Whether the VM is accessed through a reverse proxy, load balancer, or other controlled entry point is a separate network security consideration.
Where Encryption at Host becomes more valuable is when you need:
- Protection for temporary disks and host-level caches.
- End-to-end encryption coverage beyond standard storage encryption.
- Additional key management controls (for example, customer-managed keys).
- Compliance with frameworks or organizational policies that explicitly require host-level or multiple layers of encryption.
If your environment already uses Azure's default disk encryption and does not have specific compliance requirements, many organizations consider the residual risk relatively low. In practice, controls such as network segmentation, least-privilege RBAC, MFA, patch management, monitoring, and private access paths often provide a larger security benefit.
Regarding access design, the recommended approach is generally to keep VMs private (no public IPs attached directly to the VM) and expose services through Azure Load Balancer, Application Gateway, reverse proxies, Azure Bastion, VPN, or private endpoints. This reduces the attack surface and is typically easier to govern at scale.
Please refer below documentations for more details:
Security best practices for IaaS workloads in Azure