Skip to content

Commit 9574f3e

Browse files
committed
More clarity.
1 parent 9fa3c7e commit 9574f3e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

includes/virtual-machines-managed-disks-customer-managed-keys-restrictions.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
- Disks created from custom images that are encrypted using server-side encryption and customer-managed keys must be encrypted using the same customer-managed keys and must be in the same subscription.
1515
- Snapshots created from disks that are encrypted with server-side encryption and customer-managed keys must be encrypted with the same customer-managed keys.
1616
- Most resources related to your customer-managed keys (disk encryption sets, VMs, disks, and snapshots) must be in the same subscription and region.
17-
- Azure Key Vaults may be used from a different subscription but must be in the same region.
17+
- Azure Key Vaults may be used from a different subscription but must be in the same region and tenant as your disk encryption set.
1818
- Disks, snapshots, and images encrypted with customer-managed keys cannot move to another resource group and subscription.
1919
- Managed disks currently or previously encrypted using Azure Disk Encryption cannot be encrypted using customer-managed keys.
2020
- Can only create up to 1000 disk encryption sets per region per subscription.

0 commit comments

Comments
 (0)