last sync: 2022-May-23 16:32:10 UTC

Azure Policy definition

Virtual machines and virtual machine scale sets should have encryption at host enabled

Name Virtual machines and virtual machine scale sets should have encryption at host enabled
Azure Portal
Id fc4d8e41-e223-45ea-9bf5-eada37891d87
Version 1.0.0
details on versioning
Category Compute
Microsoft docs
Description Use encryption at host to get end-to-end encryption for your virtual machine and virtual machine scale set data. Encryption at host enables encryption at rest for your temporary disk and OS/data disk caches. Temporary and ephemeral OS disks are encrypted with platform-managed keys when encryption at host is enabled. OS/data disk caches are encrypted at rest with either customer-managed or platform-managed key, depending on the encryption type selected on the disk. Learn more at
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Audit, Deny, Disabled)
Used RBAC Role none
Rule Aliases IF (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Compute/virtualMachines/securityProfile.encryptionAtHost Microsoft.Compute virtualMachines properties.securityProfile.encryptionAtHost true
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.securityProfile.encryptionAtHost Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.securityProfile.encryptionAtHost false
Rule ResourceTypes IF (2)
Date/Time (UTC ymd) (i) Change type Change detail
2021-03-02 15:11:40 add fc4d8e41-e223-45ea-9bf5-eada37891d87
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: RMIT Malaysia 97a6d4f1-3bed-4cf4-ac5b-0e444c0408d6 Regulatory Compliance Preview BuiltIn
FedRAMP High d5264498-16f4-418a-b659-fa7ef418175f Regulatory Compliance GA BuiltIn
FedRAMP Moderate e95f5a9f-57ad-4d03-bb0b-b1d16db93693 Regulatory Compliance GA BuiltIn
NIST SP 800-171 Rev. 2 03055927-78bd-4236-86c0-f36125a10dc9 Regulatory Compliance GA BuiltIn
NIST SP 800-53 Rev. 4 cf25b9c1-bd23-4eb6-bd2c-f4f3ac644a5f Regulatory Compliance GA BuiltIn
NIST SP 800-53 Rev. 5 179d1daa-458f-4e47-8086-2a68d0d6c38f Regulatory Compliance GA BuiltIn