Azure Disk Encryption - Not applicable resources

Copper Contributor

I have around 350 IaaS vms that are showing up as Not Applicable within ASC across 140ish subs. I cannot seem to pin down any rhyme or reason why these machines report in this way. 

 

Here is an example of two VMs for one sub and what it looks like:

 

nathan_mitten_rpa_0-1610570352826.png

 

The VMs are on supported versions of windows, they don't have ADE extension installed, they are not on a domain, they are V1 VMs, there isn't any other software installed that would be doing encryption.

 

I've yet to find a resource that reports in in this state that actually has disk encryption enabled, so just trying to see if anyone has other thoughts on why ASC isn't reporting it as such.

 

Thanks

3 Replies

Hi Nathan,

Please check if anything on this list is applicable to your VMs: Azure Disk Encryption scenarios on Windows VMs - Azure Virtual Machines | Microsoft Docs

Thank you.

@Stanislav Belov 

I don't believe any of those apply. In some cases ADE is on the VM and has encrypted the OS disk, but it isn't applied to the data disk (at least in the portal it doesn't register ADE on the disk), but it still shows up as N/A instead of ADE missing.

In all similar cases we have seen its been something from that list that prevented ADE from being deployed to those VMs. Please review this as well:

Enable Azure Disk Encryption for Linux VMs - Azure Virtual Machines | Microsoft Docs

Enable Azure Disk Encryption for Windows VMs - Azure Virtual Machines | Microsoft Docs

If you still have hard time identifying the root cause, please consider raising a support ticket so that our engineers can help you troubleshoot the issue.

 

P.S. We are working on adding a reason why certain recommendations are not applicable to certain resources. No solid timeframe when it is going to be available though.

 

Thank you.