{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
        "slug": "dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/"
        },
        "title": "Prepare regional disk encryption sets before replicating a gallery image",
        "summary": "Can one disk encryption set cover every regional replica of a customer-key-encrypted gallery image?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:50+00:00",
        "modified_at": "2026-09-10T00:35:07+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 242,
        "potentially_affected": "Azure Compute Gallery publishers creating image versions encrypted with customer-managed keys.",
        "dse_recommendation": "Review a region-by-region encryption-set map before creating the image version.",
        "primary_source": {
            "name": "Create an encrypted image version with customer-managed keys - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Customer-key encryption for an Azure Compute Gallery image requires a disk encryption set in every replication region. Those sets must share the image&#8217;s subscription, and each region needs its own set. An image encrypted with customer-managed keys cannot return to platform-managed encryption. Such an encrypted gallery image version also cannot serve as the source for another gallery image version. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when extending image distribution to another region or designing the image&#8217;s build lineage. Confirm the planned replication destinations and whether the selected source is an already customer-key-encrypted gallery version.</p>\n<h2>DSE recommendation</h2>\n<p>Review a region-by-region encryption-set map before creating the image version. Have the image and key owners identify the intended sets by resource ID and region, including the OS disk and any included data disks. Review the source type before scheduling the build. If the workflow assumes an encrypted gallery version can be chained directly into another version, stop and redesign that source step using the documented supported path.</p>\n<h2>Verification</h2>\n<p>Inspect the created version&#8217;s regional encryption configuration and replication outcome in an authorized trial. Check every intended destination rather than inferring complete coverage from the first successful replica. Validate an approved consumer deployment separately. Keep the key-management decision and the image lineage in the release record so a later replication change does not silently rely on an unavailable regional set.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create an encrypted image version with customer-managed keys</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nCustomer-key encryption for an Azure Compute Gallery image requires a disk encryption set in every replication region. Those sets must share the image’s subscription, and each region needs its own set. An image encrypted with customer-managed keys cannot return to platform-managed encryption. Such an encrypted gallery image version also cannot serve as the source for another gallery image version. Microsoft Learn.\nApplicability\nUse this review when extending image distribution to another region or designing the image’s build lineage. Confirm the planned replication destinations and whether the selected source is an already customer-key-encrypted gallery version.\nDSE recommendation\nReview a region-by-region encryption-set map before creating the image version. Have the image and key owners identify the intended sets by resource ID and region, including the OS disk and any included data disks. Review the source type before scheduling the build. If the workflow assumes an encrypted gallery version can be chained directly into another version, stop and redesign that source step using the documented supported path.\nVerification\nInspect the created version’s regional encryption configuration and replication outcome in an authorized trial. Check every intended destination rather than inferring complete coverage from the first successful replica. Validate an approved consumer deployment separately. Keep the key-management decision and the image lineage in the release record so a later replication change does not silently rely on an unavailable regional set.\nOfficial references\nMicrosoft Learn: Create an encrypted image version with customer-managed keys. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nCustomer-key encryption for an Azure Compute Gallery image requires a disk encryption set in every replication region. Those sets must share the image’s subscription, and each region needs its own set. An image encrypted with customer-managed keys cannot return to platform-managed encryption. Such an encrypted gallery image version also cannot serve as the source for another gallery image version. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption).\n\n## Applicability\n\nUse this review when extending image distribution to another region or designing the image’s build lineage. Confirm the planned replication destinations and whether the selected source is an already customer-key-encrypted gallery version.\n\n## DSE recommendation\n\nReview a region-by-region encryption-set map before creating the image version. Have the image and key owners identify the intended sets by resource ID and region, including the OS disk and any included data disks. Review the source type before scheduling the build. If the workflow assumes an encrypted gallery version can be chained directly into another version, stop and redesign that source step using the documented supported path.\n\n## Verification\n\nInspect the created version’s regional encryption configuration and replication outcome in an authorized trial. Check every intended destination rather than inferring complete coverage from the first successful replica. Validate an approved consumer deployment separately. Keep the key-management decision and the image lineage in the release record so a later replication change does not silently rely on an unavailable regional set.\n\n## Official references\n\n[Microsoft Learn: Create an encrypted image version with customer-managed keys](https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare regional disk encryption sets before replicating a gallery image",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/",
                "headline": "Prepare regional disk encryption sets before replicating a gallery image",
                "description": "Can one disk encryption set cover every regional replica of a customer-key-encrypted gallery image?",
                "abstract": "Can one disk encryption set cover every regional replica of a customer-key-encrypted gallery image?",
                "articleBody": "Source facts\nCustomer-key encryption for an Azure Compute Gallery image requires a disk encryption set in every replication region. Those sets must share the image’s subscription, and each region needs its own set. An image encrypted with customer-managed keys cannot return to platform-managed encryption. Such an encrypted gallery image version also cannot serve as the source for another gallery image version. Microsoft Learn.\nApplicability\nUse this review when extending image distribution to another region or designing the image’s build lineage. Confirm the planned replication destinations and whether the selected source is an already customer-key-encrypted gallery version.\nDSE recommendation\nReview a region-by-region encryption-set map before creating the image version. Have the image and key owners identify the intended sets by resource ID and region, including the OS disk and any included data disks. Review the source type before scheduling the build. If the workflow assumes an encrypted gallery version can be chained directly into another version, stop and redesign that source step using the documented supported path.\nVerification\nInspect the created version’s regional encryption configuration and replication outcome in an authorized trial. Check every intended destination rather than inferring complete coverage from the first successful replica. Validate an approved consumer deployment separately. Keep the key-management decision and the image lineage in the release record so a later replication change does not silently rely on an unavailable regional set.\nOfficial references\nMicrosoft Learn: Create an encrypted image version with customer-managed keys. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:50+00:00",
                "dateModified": "2026-09-10T00:35:07+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare regional disk encryption sets before replicating a gallery image"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 242,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create an encrypted image version with customer-managed keys - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption"
                }
            }
        ]
    }
}