What you need to know
Can an existing disk encryption set be repurposed for a different encryption type?
Potentially affected
Operators planning double encryption at rest for supported Azure managed disks.
DSE recommendation
Treat the disk encryption set's encryption type as a creation-time design choice and plan a new set when the type differs.
Source facts
A disk encryption set’s encryption type cannot be changed after creation; Microsoft requires a new set for another type. The double-encryption workflow selects platform-managed plus customer-managed keys. Ultra Disk and Premium SSD v2 are excluded. The Key Vault used for managed-disk encryption must have soft delete and purge protection enabled. Microsoft Learn.
Applicability
Evaluate the exact managed disk, its storage type, and the existing encryption-set resource before choosing a deployment path. Identify the approved customer key and key-vault owner. Do not describe a disk encryption set’s fixed type as a prohibition on all future disk-encryption changes; the distinction is the resource that must be newly created.
DSE recommendation
Treat the disk encryption set’s encryption type as a creation-time design choice and plan a new set when the type differs. Make the requested type explicit in the deployment review instead of relying on an existing set’s name. Ask the security owner to confirm the key and vault protections before associating production disks. Keep the replacement set and the currently used set separately identified throughout the change.
Verification
Inspect the new set’s encryption type, key reference, and vault access before testing a disk association. Compare the disk’s resulting encryption configuration with the approved design and perform the agreed application-access test. Retain the original resource mapping until the workload owner accepts the change. Record failed key access separately from an unsupported disk type so a permission adjustment is not used to work around a capability restriction.
Official references
Microsoft Learn: Enable double encryption at rest for managed disks. Source reviewed September 9, 2026.
Review the official source
Enable double encryption at rest for managed disks - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE