What you need to know
Does enabling encryption at host on a scale set immediately encrypt every existing instance?
Potentially affected
Teams enabling encryption at host on an existing eligible Azure virtual machine scale set.
DSE recommendation
Track existing-instance deallocation and reallocation separately from the scale-set encryption setting.
Source facts
When encryption at host is enabled on an existing scale set, only subsequently created VMs are encrypted automatically; existing VMs require deallocation and reallocation. Microsoft excludes VMs and scale sets that currently use or previously used Azure Disk Encryption. The subscription feature must be registered, and the VM size must support it. For Ultra Disk and Premium SSD v2 with 512e sectors, additional disk-creation-date restrictions apply. Microsoft Learn.
Applicability
Review the intended scale set’s encryption history, VM sizes, and disk characteristics before approving the change. Separate existing instances from those expected to be created after enablement. Check the current source’s disk restrictions rather than treating support for a size as approval for every attached disk.
DSE recommendation
Track existing-instance deallocation and reallocation separately from the scale-set encryption setting. Prepare an instance-level rollout record and have the workload owner approve how service capacity will be maintained during each interruption. Resolve an Azure Disk Encryption history conflict before scheduling operations. Assign responsibility for instances that are missed, replaced, or created while the rollout is underway.
Verification
Confirm the subscription registration and intended scale-set setting, then reconcile each original instance with its approved transition evidence. Include a newly created representative instance in the acceptance test so both populations are covered. Check application behavior after the authorized operations and retain any unresolved instance explicitly. Do not close the work solely because the scale-set setting is enabled; acceptance should identify which existing instances completed the required lifecycle transition.
Official references
Microsoft Learn: Enable encryption at host using the Azure portal. Source reviewed September 9, 2026.
Review the official source
Enable end-to-end encryption using encryption at host - Azure portal - managed disks - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE