{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
        "slug": "dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/"
        },
        "title": "Account for existing scale-set instances when enabling encryption at host",
        "summary": "Does enabling encryption at host on a scale set immediately encrypt every existing instance?",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:31:04+00:00",
        "modified_at": "2026-09-10T00:35:07+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 260,
        "potentially_affected": "Teams enabling encryption at host on an existing eligible Azure virtual machine scale set.",
        "dse_recommendation": "Track existing-instance deallocation and reallocation separately from the scale-set encryption setting.",
        "primary_source": {
            "name": "Enable end-to-end encryption using encryption at host - Azure portal - managed disks - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>When encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the intended scale set&#8217;s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source&#8217;s disk restrictions rather than treating support for a size as approval for every attached disk.</p>\n<h2>DSE recommendation</h2>\n<p>Track existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.</p>\n<h2>Verification</h2>\n<p>Confirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Enable encryption at host using the Azure portal</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nWhen encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. Microsoft Learn.\nApplicability\nReview the intended scale set’s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source’s disk restrictions rather than treating support for a size as approval for every attached disk.\nDSE recommendation\nTrack existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.\nVerification\nConfirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.\nOfficial references\nMicrosoft Learn: Enable encryption at host using the Azure portal. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nWhen encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal).\n\n## Applicability\n\nReview the intended scale set’s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source’s disk restrictions rather than treating support for a size as approval for every attached disk.\n\n## DSE recommendation\n\nTrack existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.\n\n## Verification\n\nConfirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.\n\n## Official references\n\n[Microsoft Learn: Enable encryption at host using the Azure portal](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Account for existing scale-set instances when enabling encryption at host",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/",
                "headline": "Account for existing scale-set instances when enabling encryption at host",
                "description": "Does enabling encryption at host on a scale set immediately encrypt every existing instance?",
                "abstract": "Does enabling encryption at host on a scale set immediately encrypt every existing instance?",
                "articleBody": "Source facts\nWhen encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. Microsoft Learn.\nApplicability\nReview the intended scale set’s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source’s disk restrictions rather than treating support for a size as approval for every attached disk.\nDSE recommendation\nTrack existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.\nVerification\nConfirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.\nOfficial references\nMicrosoft Learn: Enable encryption at host using the Azure portal. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:31:04+00:00",
                "dateModified": "2026-09-10T00:35:07+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Account for existing scale-set instances when enabling encryption at host"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Checklist",
                    "Information priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 260,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable end-to-end encryption using encryption at host - Azure portal - managed disks - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal"
                }
            }
        ]
    }
}