Configure Azure Disk Encryption

This IT Pro Challenge virtual lab teaches how to encrypt a virtual machine’s disk using Azure’s Cloud Shell commands. Hands-on experience — creating and deploying a virtual machine and a data disk, and using a command-line interface — advances System Administrators, Cybersecurity Specialists, and Microsoft Azure Cloud Engineers career paths.

45
M
Time
Beginner
difficulty
ceu/cpe

Course Content

No items found.
No items found.
Course Description

This virtual lab will teach you how to encrypt an Azure data disk on a virtual machine. First, you will configure and connect to a virtual machine (VM) through the Remote Desktop Protocol (RDP). If you do the lab on a mac Operating System (OS), you will need Microsoft Remote Desktop. After verifying the existing machine and disk setup, you will add a new drive to the Azure VM. Finally, you will create an Azure Key Vault and implement Azure encryption, securing disk storage on the VM.

Lab exercises will guide the beginner learner, who has worked on a Windows OS and has some familiarity with the Windows command line towards successful completion. It would be helpful if lab participants set aside a full 45-minute time period as the lab takers cannot pause activities mid-way. However, users can take the virtual lab more than once. Learners will log into an Azure portal containing a resource group and permissions to initiate and configure a VM and data storage.

Legal and corporate policies require keeping data accessible for those who have permission and secure from those who do not have the authority to work with the data. For example, corporate fines for improperly protected data have resulted in fines from 124 million to 575 million dollars. This virtual lab will teach you to comply with data laws by successfully encrypting disk storage, on a VM.

System Administrators and Microsoft Azure Cloud Engineers will learn to provide safe, usable disk storage on a virtual machine. Cybersecurity Specialists will learn to assess and respond to data breach risks and threats by knowing about encryption.

Understanding the Scenario:

You are a system administrator for a company that is migrating its application services from its data center to Azure. You need to create and deploy an Azure virtual machine that hosts Windows Server 2016 Datacenter. You also need to add a data disk to the virtual machine and implement Azure Disk Encryption as a proof of concept.

Create an Azure Virtual Machine:

In this lab section, you sign in to the Azure portal and create a standard virtual machine. Then you RDP to the remote computer you created. You verify disk drives attached to the VM by using the Azure Portal and the VM’s Disk Manager.

In Azure, you set the VM size, storage space, availability, and types based on subscriptions you choose. In the lab, you select a Standard B2 with Standard Hard Disk Drive (HDD). This option provides the best storage results for infrequent access less sensitive to performance variabilities, like development and test environments. You verify the disk attached to the VM through viewing its Disk Manager.

Add a New Data Disk to the Azure Virtual Machine:

You add a new standard managed disk, in this lab exercise, by using the Azure portal. Then you format the new data disk and allocate a volume to it, using Disk Manager on the VM. Make sure you save the new drive configuration by pressing the save button at the top of the window.

First, you verify that Azure added the new data disk and then, the new volume has a healthy primary partition. A partition describes the logical section on the storage device, facilitating putting, finding and retrieving data on the disk. When creating, formatting, and assigning a volume to the new drive, you automatically create a logical partition.

Enable Azure Disk Encryption:

This lab portion has you set up a key vault and enable disk encryption using Azure Cloud Shell. Cloud Shell does not support the keyboard shortcut to paste, copied commands. But you can right-click and select paste. You can also use the up arrow to retype a previous command, helpful in the case of a mistyped command. Azure’s Disk Encryption takes ten to fifteen minutes to implement.

After you configure disk encryption, you verify successful disk configuration by connecting to the virtual machine and viewing the Disk Manager for stored data. If you see a healthy Bitlocker Encryption Key or Bek volume in the VM’s disk manager, then you have enabled Azure disk manager successfully. A Bek volume organizes all the encryption and decryption keys to get to the data.

Summary:

Upon completing this virtual lab, you will know how to create a VM with encrypted disks. You know how to:

  • Configure and connect to a VM.
  • Add a new data disk to the VM.
  • Enable Azure Disk Encryption.

With the knowledge gained from this lab, you will better comply with company and government security requirements, by creating and using a Bek volume for Azure disk encryption.

This course is part of a Career Path:
No items found.

Instructed by

Instructor
Elizabeth Sims
Provider
Cybrary Logo
Certification Body
Certificate of Completion

Complete this entire course to earn a Configure Azure Disk Encryption Certificate of Completion

Course
This is some text inside of a div block.

Configure Azure Disk Encryption

Course

This IT Pro Challenge virtual lab teaches how to encrypt a virtual machine’s disk using Azure’s Cloud Shell commands. Hands-on experience — creating and deploying a virtual machine and a data disk, and using a command-line interface — advances System Administrators, Cybersecurity Specialists, and Microsoft Azure Cloud Engineers career paths.

Path Releasing Q2 2025
Full access included with 
Insider Pro
 and 
Teams

H

45

M
Time

Beginner

i
This is some text inside of a div block.
Experience Level

i

This is some text inside of a div block.
CEU's

1

Enrollees

Heading

H

Heading

M
Time

Heading

i
This is some text inside of a div block.
Experience Level

Heading

i

This is some text inside of a div block.
CEU's

Heading

Enrollees

Learners at 96% of Fortune 1000 companies trust Cybrary

About this course

This IT Pro Challenge virtual lab teaches how to encrypt a virtual machine’s disk using Azure’s Cloud Shell commands. Hands-on experience — creating and deploying a virtual machine and a data disk, and using a command-line interface — advances System Administrators, Cybersecurity Specialists, and Microsoft Azure Cloud Engineers career paths.

Read More

Course Description

This virtual lab will teach you how to encrypt an Azure data disk on a virtual machine. First, you will configure and connect to a virtual machine (VM) through the Remote Desktop Protocol (RDP). If you do the lab on a mac Operating System (OS), you will need Microsoft Remote Desktop. After verifying the existing machine and disk setup, you will add a new drive to the Azure VM. Finally, you will create an Azure Key Vault and implement Azure encryption, securing disk storage on the VM.

Lab exercises will guide the beginner learner, who has worked on a Windows OS and has some familiarity with the Windows command line towards successful completion. It would be helpful if lab participants set aside a full 45-minute time period as the lab takers cannot pause activities mid-way. However, users can take the virtual lab more than once. Learners will log into an Azure portal containing a resource group and permissions to initiate and configure a VM and data storage.

Legal and corporate policies require keeping data accessible for those who have permission and secure from those who do not have the authority to work with the data. For example, corporate fines for improperly protected data have resulted in fines from 124 million to 575 million dollars. This virtual lab will teach you to comply with data laws by successfully encrypting disk storage, on a VM.

System Administrators and Microsoft Azure Cloud Engineers will learn to provide safe, usable disk storage on a virtual machine. Cybersecurity Specialists will learn to assess and respond to data breach risks and threats by knowing about encryption.

Understanding the Scenario:

You are a system administrator for a company that is migrating its application services from its data center to Azure. You need to create and deploy an Azure virtual machine that hosts Windows Server 2016 Datacenter. You also need to add a data disk to the virtual machine and implement Azure Disk Encryption as a proof of concept.

Create an Azure Virtual Machine:

In this lab section, you sign in to the Azure portal and create a standard virtual machine. Then you RDP to the remote computer you created. You verify disk drives attached to the VM by using the Azure Portal and the VM’s Disk Manager.

In Azure, you set the VM size, storage space, availability, and types based on subscriptions you choose. In the lab, you select a Standard B2 with Standard Hard Disk Drive (HDD). This option provides the best storage results for infrequent access less sensitive to performance variabilities, like development and test environments. You verify the disk attached to the VM through viewing its Disk Manager.

Add a New Data Disk to the Azure Virtual Machine:

You add a new standard managed disk, in this lab exercise, by using the Azure portal. Then you format the new data disk and allocate a volume to it, using Disk Manager on the VM. Make sure you save the new drive configuration by pressing the save button at the top of the window.

First, you verify that Azure added the new data disk and then, the new volume has a healthy primary partition. A partition describes the logical section on the storage device, facilitating putting, finding and retrieving data on the disk. When creating, formatting, and assigning a volume to the new drive, you automatically create a logical partition.

Enable Azure Disk Encryption:

This lab portion has you set up a key vault and enable disk encryption using Azure Cloud Shell. Cloud Shell does not support the keyboard shortcut to paste, copied commands. But you can right-click and select paste. You can also use the up arrow to retype a previous command, helpful in the case of a mistyped command. Azure’s Disk Encryption takes ten to fifteen minutes to implement.

After you configure disk encryption, you verify successful disk configuration by connecting to the virtual machine and viewing the Disk Manager for stored data. If you see a healthy Bitlocker Encryption Key or Bek volume in the VM’s disk manager, then you have enabled Azure disk manager successfully. A Bek volume organizes all the encryption and decryption keys to get to the data.

Summary:

Upon completing this virtual lab, you will know how to create a VM with encrypted disks. You know how to:

  • Configure and connect to a VM.
  • Add a new data disk to the VM.
  • Enable Azure Disk Encryption.

With the knowledge gained from this lab, you will better comply with company and government security requirements, by creating and using a Bek volume for Azure disk encryption.

Train Your Team

Cybrary’s expert-led cybersecurity courses help your team remediate skill gaps and get up-to-date on certifications. Utilize Cybrary to stay ahead of emerging threats and provide team members with clarity on how to learn, grow, and advance their careers within your organization.

Included in a Path

Elizabeth Sims
Cloud Security Architect
Read Full Bio
Learn

Learn core concepts and get hands-on with key skills.

Practice

Exercise your problem-solving and creative thinking skills with security-centric puzzles

Prove

Assess your knowledge and skills to identify areas for improvement and measure your growth

Get Hands-on Learning

Put your skills to the test in virtual labs, challenges, and simulated environments.

Measure Your Progress

Track your skills development from lesson to lesson using the Cybrary Skills Tracker.

Connect with the Community

Connect with peers and mentors through our supportive community of cybersecurity professionals.

Success from Our Learners

"Becoming a Cybrary Insider Pro was a total game changer. Cybrary was instrumental in helping me break into cybersecurity, despite having no prior IT experience or security-related degree. Their career paths gave me clear direction, the instructors had real-world experience, and the virtual labs let me gain hands-on skills I could confidently put on my resume and speak to in interviews."

Cassandra

Information Security Analyst/Cisco Systems

"I was able to earn both my Security+ and CySA+ in two months. I give all the credit to Cybrary. I’m also proud to announce I recently accepted a job as a Cyber Systems Engineer at BDO... I always try to debunk the idea that you can't get a job without experience or a degree."

Casey

Cyber Systems Engineer/BDO

"Cybrary has helped me improve my hands-on skills and pass my toughest certification exams, enabling me to achieve 13 advanced certifications and successfully launch my own business. I love the practice tests for certification exams, especially, and appreciate the wide-ranging training options that let me find the best fit for my goals"

Angel

Founder,/ IntellChromatics.

"Cybrary really helped me get up to speed and acquire a baseline level of technical knowledge. It offers a far more comprehensive approach than just learning from a book. It actually shows you how to apply cybersecurity processes in a hands-on way"

Don Gates

Principal Systems Engineer/SAIC

"Cybrary’s SOC Analyst career path was the difference maker, and was instrumental in me landing my new job. I was able to show the employer that I had the right knowledge and the hands-on skills to execute the role."

Cory

Cybersecurity analyst/

"I was able to earn my CISSP certification within 60 days of signing up for Cybrary Insider Pro and got hired as a Security Analyst conducting security assessments and penetration testing within 120 days. This certainly wouldn’t have been possible without the support of the Cybrary mentor community."

Mike

Security Engineer and Pentester/

"Becoming a Cybrary Insider Pro was a total game changer. Cybrary was instrumental in helping me break into cybersecurity, despite having no prior IT experience or security-related degree. Their career paths gave me clear direction, the instructors had real-world experience, and the virtual labs let me gain hands-on skills I could confidently put on my resume and speak to in interviews."

Cassandra

Information Security Analyst/Cisco Systems

"I was able to earn both my Security+ and CySA+ in two months. I give all the credit to Cybrary. I’m also proud to announce I recently accepted a job as a Cyber Systems Engineer at BDO... I always try to debunk the idea that you can't get a job without experience or a degree."

Casey

Cyber Systems Engineer/BDO

"Cybrary has helped me improve my hands-on skills and pass my toughest certification exams, enabling me to achieve 13 advanced certifications and successfully launch my own business. I love the practice tests for certification exams, especially, and appreciate the wide-ranging training options that let me find the best fit for my goals"

Angel

Founder,/ IntellChromatics.