{"id":259,"date":"2017-10-10T12:19:49","date_gmt":"2017-10-10T12:19:49","guid":{"rendered":"http:\/\/www.ciraltos.com\/?p=259"},"modified":"2017-10-10T12:19:49","modified_gmt":"2017-10-10T12:19:49","slug":"azure-data-encryption","status":"publish","type":"post","link":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/","title":{"rendered":"Azure Data Encryption"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-260\" src=\"\/wp-content\/uploads\/2017\/10\/DiskEncryption.png\" alt=\"Disk Encryption\" width=\"249\" height=\"249\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2017\/10\/DiskEncryption.png 249w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2017\/10\/DiskEncryption-150x150.png 150w\" sizes=\"(max-width: 249px) 100vw, 249px\" \/>As of today, Microsoft has a few different ways of encrypting Azure data.\u00a0 \u00a0The options for Azure Data Encryption on servers include Storage Service Encryption and Azure Disk Encryption.\u00a0 Below is a quick summery of each.<\/p>\n<h4>Storage Service Encryption (SSE)<\/h4>\n<p>This is at the storage account level and encrypts data at rest.\u00a0 Encryption takes place as the data is written to storage and decrypted when it\u2019s read.<!--more--><\/p>\n<p>Pros: Easiest to implement by selecting an option on the storage account.\u00a0 Satisfies the \u201cis data encrypted at rest\u201d requirement of most audits.\u00a0 Available on all types of storage in all regions.\u00a0 Enabled by default on new storage accounts.<\/p>\n<p>Cons: Data is decrypted before it\u2019s passed over the network (however, HTTPS or SMB 3.0 can be enforced to encrypted data in flight).\u00a0 Microsoft keys used by default.\u00a0 There is an option to use your own keys but they are stored in the Microsoft Key Vault (feature in preview, not GA).<\/p>\n<h4>Azure Disk Encryption<\/h4>\n<p>Virtual drive encryption, BitLocker on Windows or DM-Crypt on Linux.<\/p>\n<p>Pros: Generally Available.\u00a0 Virtual hard drives are unusable without the key.<\/p>\n<p>Cons: Keys are managed in the Microsoft Key Vault.\u00a0 More complicated to setup and adds extra steps to data recovery.\u00a0 Not supported on Basic tier VM\u2019s.<\/p>\n<p>*Please note, if you are using Azure Disk Encryption you must use the Key Encryption Key (KEK) method to encrypt the drives.\u00a0 You will not be able to backup servers unless you use KEK.<\/p>\n<p>The performance impact of SSE is inconsequential.\u00a0 Only new data written to the storage account is encrypted after enabling SSE.\u00a0 Is situations where all data needs to be encrypted, it will be necessary to create a new storage account with encryption enabled and copy the data to it.<\/p>\n<p>The only time you may consider disabling SSE is on storage accounts that house virtual disks encrypted with disk encryption.\u00a0 This would avoid double encryption.\u00a0 However, there is no downside to having encryption on the storage account that have encrypted disks.\u00a0 All new storage accounts now has SSE on by default and Microsoft has no recommendations to disable encryption in these scenarios.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As of today, Microsoft has a few different ways of encrypting Azure data.\u00a0 \u00a0The options for Azure Data Encryption on servers include Storage Service Encryption and Azure Disk Encryption.\u00a0 Below is a quick summery of each. Storage Service Encryption (SSE) This is at the storage account level and encrypts data at rest.\u00a0 Encryption takes place &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\"> <span class=\"screen-reader-text\">Azure Data Encryption<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"default","ast-global-header-display":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":""},"categories":[2],"tags":[9,151,149,152,148,75,39,150,26],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Azure Data Encryption - ciraltos<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Azure Data Encryption - ciraltos\" \/>\n<meta property=\"og:description\" content=\"As of today, Microsoft has a few different ways of encrypting Azure data.\u00a0 \u00a0The options for Azure Data Encryption on servers include Storage Service Encryption and Azure Disk Encryption.\u00a0 Below is a quick summery of each. Storage Service Encryption (SSE) This is at the storage account level and encrypts data at rest.\u00a0 Encryption takes place &hellip; Azure Data Encryption Read More &raquo;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\" \/>\n<meta property=\"og:site_name\" content=\"ciraltos\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-10T12:19:49+00:00\" \/>\n<meta name=\"author\" content=\"Travis Roberts\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ciraltos\" \/>\n<meta name=\"twitter:site\" content=\"@ciraltos\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Travis Roberts\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\"},\"author\":{\"name\":\"Travis Roberts\",\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"headline\":\"Azure Data Encryption\",\"datePublished\":\"2017-10-10T12:19:49+00:00\",\"dateModified\":\"2017-10-10T12:19:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\"},\"wordCount\":356,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"keywords\":[\"Azure\",\"bitlocker\",\"disk\",\"dm-crypt\",\"encryption\",\"server\",\"storage\",\"storage account\",\"VM\"],\"articleSection\":[\"Azure\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\",\"url\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\",\"name\":\"Azure Data Encryption - ciraltos\",\"isPartOf\":{\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#website\"},\"datePublished\":\"2017-10-10T12:19:49+00:00\",\"dateModified\":\"2017-10-10T12:19:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\/\/www.ciraltos.com\/staging2\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure Data Encryption\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#website\",\"url\":\"http:\/\/www.ciraltos.com\/staging2\/\",\"name\":\"ciraltos\",\"description\":\"cloud, technology and trends\",\"publisher\":{\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/www.ciraltos.com\/staging2\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\",\"name\":\"Travis Roberts\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png\",\"contentUrl\":\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png\",\"width\":5657,\"height\":3563,\"caption\":\"Travis Roberts\"},\"logo\":{\"@id\":\"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/www.ciraltos.com\",\"https:\/\/twitter.com\/ciraltos\"],\"url\":\"https:\/\/www.ciraltos.com\/staging2\/author\/admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Azure Data Encryption - ciraltos","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/","og_locale":"en_US","og_type":"article","og_title":"Azure Data Encryption - ciraltos","og_description":"As of today, Microsoft has a few different ways of encrypting Azure data.\u00a0 \u00a0The options for Azure Data Encryption on servers include Storage Service Encryption and Azure Disk Encryption.\u00a0 Below is a quick summery of each. Storage Service Encryption (SSE) This is at the storage account level and encrypts data at rest.\u00a0 Encryption takes place &hellip; Azure Data Encryption Read More &raquo;","og_url":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/","og_site_name":"ciraltos","article_published_time":"2017-10-10T12:19:49+00:00","author":"Travis Roberts","twitter_card":"summary_large_image","twitter_creator":"@ciraltos","twitter_site":"@ciraltos","twitter_misc":{"Written by":"Travis Roberts","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#article","isPartOf":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/"},"author":{"name":"Travis Roberts","@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"headline":"Azure Data Encryption","datePublished":"2017-10-10T12:19:49+00:00","dateModified":"2017-10-10T12:19:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/"},"wordCount":356,"commentCount":0,"publisher":{"@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"keywords":["Azure","bitlocker","disk","dm-crypt","encryption","server","storage","storage account","VM"],"articleSection":["Azure"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/","url":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/","name":"Azure Data Encryption - ciraltos","isPartOf":{"@id":"http:\/\/www.ciraltos.com\/staging2\/#website"},"datePublished":"2017-10-10T12:19:49+00:00","dateModified":"2017-10-10T12:19:49+00:00","breadcrumb":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-data-encryption\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/www.ciraltos.com\/staging2\/"},{"@type":"ListItem","position":2,"name":"Azure Data Encryption"}]},{"@type":"WebSite","@id":"http:\/\/www.ciraltos.com\/staging2\/#website","url":"http:\/\/www.ciraltos.com\/staging2\/","name":"ciraltos","description":"cloud, technology and trends","publisher":{"@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/www.ciraltos.com\/staging2\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a","name":"Travis Roberts","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/","url":"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png","contentUrl":"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png","width":5657,"height":3563,"caption":"Travis Roberts"},"logo":{"@id":"http:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/www.ciraltos.com","https:\/\/twitter.com\/ciraltos"],"url":"https:\/\/www.ciraltos.com\/staging2\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/259"}],"collection":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/comments?post=259"}],"version-history":[{"count":2,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/259\/revisions"}],"predecessor-version":[{"id":262,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/259\/revisions\/262"}],"wp:attachment":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/media?parent=259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/categories?post=259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/tags?post=259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}