Compute security
CoreEncryption at host
VM host encryption for temporary disks, caches, and host-to-storage flows.
Key points
- Encrypts VM temporary disks and disk caches at the compute host.
- Also protects data flowing from the host to the Storage service.
- Availability depends on supported VM sizes, regions, and subscription configuration; ADE is a separate guest-based approach with announced retirement.
Best-known use cases
- Protect temporary and cache paths for a supported VM.
- Meet a requirement for host-level encryption coverage.
What candidates often confuse it with
- Encryption at host vs Azure Disk Encryption: platform host protection vs the separate older guest-based BitLocker or DM-Crypt approach.
- Encryption at host vs storage service encryption: compute-host path coverage vs stored data encryption.
Key takeaway
When a requirement names encryption at host, do not substitute ADE; Microsoft recommends encryption at host or other platform options for new VMs because ADE retirement has been announced.
Related services
- Azure Virtual Machines
- Azure managed disks
Relevant exam tasks
- D3.2.S1 — Create a virtual machine
- D3.2.S2 — Configure encryption at host for Azure virtual machines
- D3.2.S3 — Move a virtual machine to another resource group, subscription, or region
- D3.2.S4 — Manage virtual machine sizes
- D3.2.S5 — Manage virtual machine disks