# Choose the disk encryption set's type before enabling double encryption

> Can an existing disk encryption set be repurposed for a different encryption type?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-051-choose-the-disk-encryption-set-s-type-before-enabling-double-encryption/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:05+00:00
- Modified: 2026-09-10T00:35:07+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can an existing disk encryption set be repurposed for a different encryption type?

## Potentially affected

Operators planning double encryption at rest for supported Azure managed disks.

## DSE recommendation

Treat the disk encryption set's encryption type as a creation-time design choice and plan a new set when the type differs.

## Article

## Source facts

A disk encryption set’s encryption type cannot be changed after creation; Microsoft requires a new set for another type. The double-encryption workflow selects platform-managed plus customer-managed keys. Ultra Disk and Premium SSD v2 are excluded. The Key Vault used for managed-disk encryption must have soft delete and purge protection enabled. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-double-encryption-at-rest-portal).

## Applicability

Evaluate the exact managed disk, its storage type, and the existing encryption-set resource before choosing a deployment path. Identify the approved customer key and key-vault owner. Do not describe a disk encryption set’s fixed type as a prohibition on all future disk-encryption changes; the distinction is the resource that must be newly created.

## DSE recommendation

Treat the disk encryption set’s encryption type as a creation-time design choice and plan a new set when the type differs. Make the requested type explicit in the deployment review instead of relying on an existing set’s name. Ask the security owner to confirm the key and vault protections before associating production disks. Keep the replacement set and the currently used set separately identified throughout the change.

## Verification

Inspect the new set’s encryption type, key reference, and vault access before testing a disk association. Compare the disk’s resulting encryption configuration with the approved design and perform the agreed application-access test. Retain the original resource mapping until the workload owner accepts the change. Record failed key access separately from an unsupported disk type so a permission adjustment is not used to work around a capability restriction.

## Official references

[Microsoft Learn: Enable double encryption at rest for managed disks](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-double-encryption-at-rest-portal). Source reviewed September 9, 2026.

## Primary reference

- Name: Enable double encryption at rest for managed disks - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-double-encryption-at-rest-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose the disk encryption set's type before enabling double encryption,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-051-choose-the-disk-encryption-set-s-type-before-enabling-double-encryption/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
