# Prepare regional disk encryption sets before replicating a gallery image

> Can one disk encryption set cover every regional replica of a customer-key-encrypted gallery image?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:50+00:00
- Modified: 2026-09-10T00:35:07+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can one disk encryption set cover every regional replica of a customer-key-encrypted gallery image?

## Potentially affected

Azure Compute Gallery publishers creating image versions encrypted with customer-managed keys.

## DSE recommendation

Review a region-by-region encryption-set map before creating the image version.

## Article

## Source facts

Customer-key encryption for an Azure Compute Gallery image requires a disk encryption set in every replication region. Those sets must share the image’s subscription, and each region needs its own set. An image encrypted with customer-managed keys cannot return to platform-managed encryption. Such an encrypted gallery image version also cannot serve as the source for another gallery image version. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption).

## Applicability

Use this review when extending image distribution to another region or designing the image’s build lineage. Confirm the planned replication destinations and whether the selected source is an already customer-key-encrypted gallery version.

## DSE recommendation

Review a region-by-region encryption-set map before creating the image version. Have the image and key owners identify the intended sets by resource ID and region, including the OS disk and any included data disks. Review the source type before scheduling the build. If the workflow assumes an encrypted gallery version can be chained directly into another version, stop and redesign that source step using the documented supported path.

## Verification

Inspect the created version’s regional encryption configuration and replication outcome in an authorized trial. Check every intended destination rather than inferring complete coverage from the first successful replica. Validate an approved consumer deployment separately. Keep the key-management decision and the image lineage in the release record so a later replication change does not silently rely on an unavailable regional set.

## Official references

[Microsoft Learn: Create an encrypted image version with customer-managed keys](https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption). Source reviewed September 9, 2026.

## Primary reference

- Name: Create an encrypted image version with customer-managed keys - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/image-version-encryption
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare regional disk encryption sets before replicating a gallery image,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-066-prepare-regional-disk-encryption-sets-before-replicating-a-gallery-image/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
