# Account for existing scale-set instances when enabling encryption at host

> Does enabling encryption at host on a scale set immediately encrypt every existing instance?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:04+00:00
- Modified: 2026-09-10T00:35:07+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does enabling encryption at host on a scale set immediately encrypt every existing instance?

## Potentially affected

Teams enabling encryption at host on an existing eligible Azure virtual machine scale set.

## DSE recommendation

Track existing-instance deallocation and reallocation separately from the scale-set encryption setting.

## Article

## Source facts

When encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal).

## Applicability

Review the intended scale set’s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source’s disk restrictions rather than treating support for a size as approval for every attached disk.

## DSE recommendation

Track existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.

## Verification

Confirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.

## Official references

[Microsoft Learn: Enable encryption at host using the Azure portal](https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal). Source reviewed September 9, 2026.

## Primary reference

- Name: Enable end-to-end encryption using encryption at host - Azure portal - managed disks - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Account for existing scale-set instances when enabling encryption at host,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-052-account-for-existing-scale-set-instances-when-enabling-encryption-at-host/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
