Applying Azure Disk Encryption to a Windows Virtual Machine
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Remote Desktop |
| Completed | 2026 |
Overview
Azure Disk Encryption (ADE) uses BitLocker to encrypt Windows VM disks at rest, with encryption keys stored and managed in Azure Key Vault. In this lab, I secured a Windows Server VM by enabling disk encryption on both the OS and data disks, deploying a dedicated Key Vault with disk encryption access enabled, creating an encryption key, and confirming the encryption was applied — both through the Azure portal and by verifying BitLocker status directly on the VM via Remote Desktop.
What I Did
- Opened the vmw-awesome virtual machine's Disks blade and navigated to Additional settings to initiate disk encryption configuration
- Selected "OS and data disks" as the encryption scope, triggering the Key Vault setup workflow
- Created a new Key Vault with a globally unique name, 7-day soft delete retention, purge protection disabled, and Azure Disk Encryption for volume encryption enabled under Access Configuration
- Created a new encryption key (awesomekey) in the Key Vault and selected the current key version for use
- Saved the disk encryption settings and waited for the deployment to complete
- Verified in the Disks blade that the Encryption field updated to "SSE with PMK & ADE", confirming Azure Disk Encryption was applied
- Confirmed the AzureDiskEncryption extension appeared in the VM's Extensions + applications blade
- Connected to the VM via Remote Desktop and opened Manage BitLocker, confirming Windows (C:) showed BitLocker encrypting or BitLocker on for the OS drive
← Back to Pluralsight Labs