Soru

Zorluk: ZorAzure Virtual Machine Backup Configuration

An organization implements virtual machine encryption using Server-Side Encryption with Customer-Managed Keys (SSE with CMK). You are configuring backups for `vm-secops-prd01`, a virtual machine running Windows Server 2022 Datacenter in the North Europe region. The disk encryption keys for this VM reside in an Azure Key Vault named `kv-secops-vault`. You have deployed a Recovery Services Vault named `rsv-secops-backups` in the same region. To enable successful backup operations for this encrypted virtual machine, which two configurations must you apply? (Select two.)

  1. A
    Deploy the Recovery Services Vault in the West Europe region to enable cross-region protection.
  2. Configure a system-assigned managed identity for the Recovery Services Vault.Cevap
  3. C
    Assign the Key Vault Crypto Service Encryption User role to the system-assigned managed identity of the virtual machine.
  4. Grant the Recovery Services Vault's managed identity the Key Vault Crypto Service Encryption User role on the Key Vault.Cevap

Cevap

Configure a system-assigned managed identity for the Recovery Services Vault, and grant the Recovery Services Vault's managed identity the Key Vault Crypto Service Encryption User role on the Key Vault.
For virtual machines using Server-Side Encryption with Customer-Managed Keys (SSE with CMK), the backup process requires the Recovery Services Vault to access the Key Vault containing the disk encryption keys. This is achieved by enabling a system-assigned managed identity on the Recovery Services Vault and assigning it the Key Vault Crypto Service Encryption User role on the Key Vault, which grants the required wrap and unwrap key permissions.

Adım Adım Çözüm

1
Ensure the Recovery Services Vault is in the same region as the virtual machine.
The vault must be in North Europe to perform backups for the VM in North Europe.
Cross-region backups of virtual machines are not supported for standard vault backup operations.
2
Enable system-assigned managed identity on the Recovery Services Vault.
An identity is registered for the Recovery Services Vault in Microsoft Entra ID.
Azure Backup needs an identity to authenticate to Key Vault and access key encryption keys.
3
Assign the Key Vault Crypto Service Encryption User role on the Key Vault to the Recovery Services Vault's managed identity.
The vault is authorized to read, wrap, and unwrap keys in the Key Vault.
This permission allows Azure Backup to run backup and restore operations on disks encrypted with SSE with CMK.

Anahtar Kavram

Backup configuration for VMs encrypted with Server-Side Encryption using Customer-Managed Keys (SSE with CMK).
Tahmini Süre:2m 0s
Bu soruyu puanla