Implement security for servers and virtual machines (VMs)
Unlock the complete study guide + 1,040 practice questions across 16 full exams.
Bundled into the existing SC-500 premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- One machine, five control points
- Where disk encryption happens in the stack
- Customer-managed keys and the disk encryption set
- Migrating off Azure Disk Encryption before it retires
- Reaching the machine with Azure Bastion
- Just-in-time VM access, from request to expiry
- Bringing non-Azure servers into scope with Azure Arc
- Selecting and scoping a Defender for Servers plan
- Keeping a third-party antivirus without losing EDR
- Agentless machine scanning
- The gap between a plan and a running control
- Boot integrity with trusted launch
- Enforcing guest settings with Azure Machine Configuration
- Exam-pattern recognition
Disk encryption at rest: what each of the four options covers
| Property | Storage server-side encryption | Encryption at host | Azure Disk Encryption | Confidential disk encryption |
|---|---|---|---|---|
| Where encryption happens | Azure Storage clusters | The VM host | Inside the guest OS (BitLocker or dm-crypt) | Bound to the confidential VM's vTPM |
| OS and data disks at rest | Yes | Yes | Yes | Yes, OS disk is the protected scope |
| Temporary disk | No | Yes, with platform-managed keys | Yes | Opt-in |
| Disk caches | No | Yes | Yes | Yes |
| Data encrypted between compute and storage | No | Yes | Yes | Yes |
| Customer-managed keys | With a disk encryption set | With a disk encryption set | With a key encryption key in Key Vault | With a disk encryption set |
| Consumes the VM's CPU | No | No | Yes | Yes |
| Lifecycle to plan around | Always on for managed disks | Enable per VM or scale set; supported size and region needed | Retires September 15, 2028 | Confidential VM sizes only |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
References
- Server-side encryption of Azure managed disks
- Overview of managed disk encryption options
- About Azure confidential VMs
- Use the Azure portal to enable server-side encryption with customer-managed keys for managed disks
- What is Azure Bastion?
- About Azure Bastion configuration settings
- Deploy private-only Bastion
- Understand just-in-time virtual machine access
- Enable just-in-time access
- Azure Arc-enabled servers overview
- VM extension management with Azure Arc-enabled servers
- Connect on-premises machines to Microsoft Defender for Cloud
- Select a Defender for Servers plan
- Enable Defender for Endpoint integration in Microsoft Defender for Cloud
- Onboard Windows Servers using a local script
- Microsoft Defender Antivirus compatibility with other security products
- Endpoint detection and response in block mode
- Agentless machine scanning in Microsoft Defender for Cloud
- Enable agentless machine scanning
- Enable vulnerability scanning with Microsoft Defender Vulnerability Management
- Overview of file integrity monitoring in Microsoft Defender for Cloud
- Trusted launch for Azure VMs
- What is Azure Machine Configuration?
- Understand machine configuration assignment resources