When you create a Cloud VM Set, you can specify that, when a VM is registered with the Cloud VM Set, Cryptographic Security Platform Vault will automatically tell the Policy Agent on that VM to encrypt the available drives on the VM. If you enable this feature, you can also specify an Automatic Data Encryption Policy that tells Cryptographic Security Platform Vault which drives to include or exclude by default.

For example, If you enable Automatic Data Encryption and you want to:

  • Automatically encrypt all available drives on the VM except the C: drive, you would set the Automatic Data Encryption Policy to Exclude the C: drive.
  • Automatically encrypt only the C: drive, you would set the Automatic Data Encryption Policy to Include the C: drive.
  • Automatically encrypt all available drives on the VM including the C: drive, you would set the Automatic Data Encryption Policy to Encrypt All Devices.

You can specify as many paths in the Automatic Data Encryption Policy as you want, and you can specify a mixture of Windows drives and Linux device names. You cannot, however, set some paths as included and some as excluded. The Automatic Data Encryption Policy must be configured to either exclude all of the specified paths or include all of the specified paths.

When you register a VM with the Cloud VM Set, the VM inherits the Automatic Data Encryption settings from the Cloud VM Set. You can override the default settings for an individual VM at any time, allowing you to customize the Automatic Data Encryption feature on a VM-by-VM basis.

This section includes: