last sync: 2022-Jun-28 16:32:57 UTC

Azure Policy definition

Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption

Name Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption
Azure Portal
Id d461a302-a187-421a-89ac-84acdb4edc04
Version 2.0.0
details on versioning
Category Compute
Microsoft docs
Description Requiring a specific set of disk encryption sets to be used with managed disks give you control over the keys used for encryption at rest. You are able to select the allowed encrypted sets and all others are rejected when attached to a disk. Learn more at https://aka.ms/disks-cmk.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Audit, Deny, Disabled)
Used RBAC Role none
Rule Aliases IF (9)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Compute/disks/encryption.diskEncryptionSetId Microsoft.Compute disks properties.encryption.diskEncryptionSetId true
Microsoft.Compute/disks/managedBy Microsoft.Compute disks managedBy false
Microsoft.Compute/galleries/images/versions/publishingProfile.targetRegions[*].encryption.dataDiskImages[*].diskEncryptionSetId Microsoft.Compute galleries/images/versions properties.publishingProfile.targetRegions[*].encryption.dataDiskImages[*].diskEncryptionSetId false
Microsoft.Compute/galleries/images/versions/publishingProfile.targetRegions[*].encryption.osDiskImage.diskEncryptionSetId Microsoft.Compute galleries/images/versions properties.publishingProfile.targetRegions[*].encryption.osDiskImage.diskEncryptionSetId false
Microsoft.Compute/images/storageProfile.dataDisks[*].diskEncryptionSet.id Microsoft.Compute images properties.storageProfile.dataDisks[*].diskEncryptionSet.id false
Microsoft.Compute/images/storageProfile.osDisk.diskEncryptionSet.id Microsoft.Compute images properties.storageProfile.osDisk.diskEncryptionSet.id false
Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachines properties.storageProfile.osDisk.managedDisk.diskEncryptionSet.id true
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.dataDisks[*].managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.storageProfile.dataDisks[*].managedDisk.diskEncryptionSet.id false
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.osDisk.managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.storageProfile.osDisk.managedDisk.diskEncryptionSet.id false
Rule ResourceTypes IF (5)
Microsoft.Compute/disks
Microsoft.Compute/galleries/images/versions
Microsoft.Compute/images
Microsoft.Compute/virtualMachines
Microsoft.Compute/virtualMachineScaleSets
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-03-09 14:37:41 change Major (1.0.0 > 2.0.0)
2021-03-02 15:11:40 add d461a302-a187-421a-89ac-84acdb4edc04
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: Reserve Bank of India - IT Framework for NBFC 7f89f09c-48c1-f28d-1bd5-84f3fb22f86c Regulatory Compliance Preview BuiltIn
[Preview]: RMIT Malaysia 97a6d4f1-3bed-4cf4-ac5b-0e444c0408d6 Regulatory Compliance Preview BuiltIn
JSON Changes

JSON