Use the Azure portal to enable end-to-end encryption using encryption at host
By: Date: 24/09/2026 Categories: azure Tags:

Encryption at Host (EaH) encrypts data at the hypervisor level, ensuring data is encrypted end-to-end—from the application down to storage, including in-memory data. This complements Azure Storage Service Encryption (SSE) and Network encryption (e.g., TLS) for full protection. Below are the steps to enable EaH via the Azure portal for both new and existing VMs.


Prerequisites

  1. Supported VM SKUs:
    • Windows: Esv3, Edv3, Bs_v2, or later generations.
    • Linux: Esv3, Edv3, nvv4, or later generations.
    • Note: EaH is not supported on older SKUs (e.g., Dv2, Dv3).
  2. Supported OS:
    • Windows: Windows Server 2019 or later.
    • Linux: Ubuntu 18.04+, RHEL 8+, SLES 15+, or later (with kernel support for encrypted disks).
  3. Key Vault:
    • A Key Vault in the same Azure region as your VM.
    • A customer-managed key (CMK) stored in the Key Vault (RSA or EC key).
    • Key Vault must have:
      • Enabled for trusted services (allow Azure Virtual Machines to access the key).
      • Key permissions: Encrypt, Decrypt, WrapKey, UnwrapKey.
  4. Azure Portal Access:
    • You must have Contributor or Owner permissions on the resource group.

Step 1: Prepare Key Vault and Customer-Managed Key

  1. Navigate to Key Vaults in Azure Portal.
  2. Create a new Key Vault (or use an existing one):
    • Ensure it’s in the same region as your VM.
    • Under Access policies, ensure “Enable trusted services to access this key vault” is checked.
    • Save.
  3. Create a Key:
    • Open the Key Vault → Keys → Generate/Import.
    • Choose RSA (2048-bit or 4096-bit) or EC (P-256, P-384).
    • Set Key usage to Encrypt, Decrypt, Wrap Key, Unwrap Key.
    • Save the key (e.g., EaH-Key).

**Step 2: Enable Encryption at Host for a New VM`

Option A: During VM Creation

  1. Create a Virtual Machine:
    • Go to Virtual Machines → + Create → Virtual Machine.
    • Fill in basics (name, region, resource group).
  2. Configure VM Settings:
    • On the Basics tab, select a supported VM size (e.g., Standard_E2s_v3).
    • On the Settings tab:
      • OS Disk section → Expand Advanced settings.
      • Check Enable Encryption at Host.
      • Select the Key Vault and Key created earlier.
    Enable EaH in VM creation
  3. Complete Configuration:
    • Configure OS, authentication, network, etc.
    • Review and create the VM.
  4. Verify EaH:
    • After deployment, go to the VM → Settings → Encryption.
    • Confirm Encryption at Host is Enabled and shows the key vault/key.

Step 3: Enable Encryption at Host for an Existing VM

Option B: Update an Existing VM

  1. Stop the VM:
    • Go to your VM → Stop (EaH cannot be enabled on a running VM for most SKUs).
  2. Enable EaH:
    • Navigate to VM → Settings → Encryption.
    • Under Encryption at Host, click Enable.
    • Select the Key Vault and Key from your prepared Key Vault.
    • Save changes.
  3. Start the VM:
    • Restart the VM after saving.
  4. Verify:
    • Return to Encryption settings → Confirm Encryption at Host is Enabled.

Step 4: Verify End-to-End Encryption

1. Confirm EaH Status

  • Portal:
    VM → Settings → Encryption → Check Encryption at Host status.
  • CLI (optional):az vm show --resource-group --name --query "hardwareProfile.encryptionAtHost" Output should be true.

2. Validate Data Protection

  • In-Memory Encryption: EaH encrypts data in memory at the hypervisor, so applications cannot read plaintext data from memory dumps.
  • Disk Encryption: EaH works with Azure Disk Encryption (ADE) for OS/data disks. Ensure both are configured if needed.

3. Network Encryption

  • Ensure TLS/SSL is enforced for all management and application traffic (e.g., via Azure Application Gateway, Front Door, or VM HTTPS).
  • Use Azure Security Center to audit network security.

Security Best Practices

  1. Key Vault Security:
    • Restrict access to the Key Vault using Azure RBAC and network ACLs.
    • Enable Key Vault rotation and auto-rotation for the CMK.
    • Audit key usage via Azure Monitor and Key Vault logs.
  2. VM Access Control:
    • Use Azure Disk Encryption alongside EaH for additional disk encryption.
    • Apply NSGs and Azure Firewall to restrict unauthorized network access.
  3. Compliance:
    • EaH supports NIST 800-53, ISO 27001, and GDPR compliance.
    • Document EaH enablement in your compliance reports.
  4. Monitoring:
    • Enable Azure Policy to enforce EaH on all VMs.
    • Use Azure Monitor to alert on EaH configuration changes.

Troubleshooting

  • VM Size Not Supported?
    Upgrade the VM to a supported SKU (e.g., from Dv2 to Esv3).
  • Key Vault Access Denied?
    Ensure the Key Vault allows trusted services and the VM’s managed identity has access.
  • Linux OS Compatibility?
    Verify the OS version supports EaH (e.g., Ubuntu 20.04+). Use cat /proc/diskstats to check encryption status.

By following these steps, you ensure end-to-end encryption by enabling Encryption at Host, protecting data at rest, in transit, and in memory. This aligns with Azure’s security best practices for compliance and data sovereignty.

Reference- Use the Azure portal to enable end-to-end encryption using encryption at host