How to Encrypt an Existing or New Virtual Machine (2024)

Table of Contents

What is an encrypted virtual machine

In VMware environment, the hypervisor encryption feature is first available in VMware vSphere 6.5. You can enableVMEncryption policy to create an encrypted virtual machine. For Hyper-V VM encryption, BitLocker is needed to encrypt virtual machines and disks.

Virtual machine with encryption feature is able to encrypt I/Os before data gets stored in the VMDK. An encrypted virtual machine makes sure someone does not have unauthorized access to your data.

Should you encrypt virtual machine in VMware

Data security of virtual machines is very important for enterprises. An encrypted virtual machine protects the sensitive data and enhances business security. At the same time, virtual machines are very vulnerable when performing vMotion, any changes may causethe failure of vMotion operation. Encrypting virtual machines and virtual disks ensures the security of VM data while transferring.

In this article, I will demonstrate the procedures to encrypt virtual machinein VMware. You can encrypt virtual machines or virtual disks by changing a storage policy.

  • Create a new encrypted virtual machine
  • Encrypt an existing VM in VMware
  • Efficient method to protect VM security

Prerequisites to encrypt VMware VM

Before creating an encrypted virtual machine, the following points are worth noting.

1. Ensure the virtual machine that needs be encrypted is powered off.

2. Create a VM encryption storage policy.

3. Establish a trusted connection with the KMS and select a default KMS.

4. Verify that you have the required privileges:

  • Cryptographic operations. Encrypt new.
  • If the host encryption mode is not Enabled, you also need Cryptographic operations. Register host.

How to encrypt VMware virtual machine

In this section, I will explain how to create a new encrypted virtual machine and how to encrypt an existing virtual machine with the hypervisor encryption feature in detail.

Create a new encrypted virtual machine

1. Navigate to the virtual machine in the vSphere Client inventory, and click New Virtual Machine.

2. Select Create a new virtual machine >> enter a new name for the VM >> select a location >> select the destination computer resource.

3. On the Select storage page, you should enable Encrypt this virtual machine. Then select VM Encryption Policy.

4. Select compatibility as ESXi 6.5 and later which allows you to migrate the encrypted virtual machine to the hosts with compatibility. Then select a guest OS that will be installed on the VM.

5. On Customize hardware page, configure the hardware such as CPU, memory……

Click VM Options >> Encryption. Specify the virtual disk to be encrypted or decrypted. You can also change the Encrypted vMotion setting to encrypt transferring process.

Or you can back to Virtual Hardware page to select ADD NEW DEVICE >> Hard Disk, then specify the VM storage policy for each disk.

6. Review the information, and click Finish.

After you have encrypted your virtual machines, you can access to Summary on the main screen to check if the virtual machine is encrypted successfully. Click Encryption to see VM configuration files are encrypted. Hard disk is encrypted.

Tips: An encrypted virtual machine may consist ofencrypted disks or VM home files. But you cannot encrypt the virtual disk of an unencrypted virtual machine, which means if you want to encrypt a virtual disk, please encrypt this virtual machine first.

Encrypt an existing VM in VMware

1. Log in vSphere Client, and connect to vCenter Sever.

2. Right-click the virtual machine you want to encrypt, and select VM Policies >> Edit VM Storage Policies.

3. In VM storage policy, select VM Encryption Policy. Click OK.

Back to the main screen, you can monitor the process of reconfiguration of VM disks and VM home. If you only want to enable encryption feature for part of VM, please read the following steps.

4. Click Edit VM Storage Policy >> Configure per disk. Select Datastore Default for unencrypted disks. Click OK.

Free method to protect VMware VMsecurity

For businesses, data security is life. In general, you can't predict if you will lose your data in the next second. Power outages, natural disasters, virus software or careless human error can easily result in serious financial losses. 20 percent of companies who experienced data loss from outages said it cost them between $50,000 and $5 million. So, how to protect your important VM data is the point discussed in this part.

Here, I’d like to apply a free VMware backup software -AOMEI Cyber Backup to provide continuous protections for virtual machines. With this professional tool, you can get the following benefits.

Perpetual free: no time limit for AOMEI Cyber Backup Free Edition.
Support free ESXi: supports both paid and free versions of VMware ESXi.
Easy-to-use: backup and restore multiple virtual machines via central console without complicated configuration and reinstallation.
Automatically run backup tasks: It can auto backup virtual machines on regular basis to protect VMware workloads continuously.
Flexible backup strategies: It creates full backup for entire VM, or incremental/differential backup.
Instant Disaster Recovery: Once the VMware crashes, it can quickly restore VM to normal state and reduce business-critical downtime.

Please hit the button below to download and use AOMEI Cyber Backup for free:

Secure Download

*You can choose to install this VM backup software on either Windows or Linux system.

Steps to create a highly secure backup task for free:

1. Install AOMEI Cyber Backup and add vCenter or Standalone ESXihost as the source device. And then click Backup Task >> Create New Task.

2. Enter a name for backup task and select VMware ESXi Backup. Then select one or more virtual machines for backup.

3. Choose the backupTarget to place backup files. You can store the files to network or local destination.

3. Select backup method and specify the time to run the task automatically. It is flexible to choose time period as daily, weekly, monthly by date or monthly by week

4. Once your original VM corrupts, you can restore the entire VMto its normal status from any selected backup version. It saves your time to reinstall applications or configure multiple VMs.

✍ While the Free Edition covers most of the VM backup needs, you can also upgrade to Premium Edition to enjoy:
✦ Batch VM Backup:batch backup large numbers of VMs managed by vCenter Serverorstandalone ESXi hosts.
✦ Backup Cleanup: Configure retention policy to auto delete the old backup files and save storage space.
✦ Restore to new location: Easily make a clone of a virtual machine in the same or another datastore/host, without reinstalling or configuring a new VM.

Summary

An encrypted virtual machine enjoys a high degree of data privacy. This article includes the detailed steps to encrypt an existing VM and create a new encrypted virtual machine. In addition to encryption, you can also backupVMwareto achieve efficient VM encryption.

How to Encrypt an Existing or New Virtual Machine (2024)

FAQs

How do you encrypt your virtual machine? ›

Encrypt the virtual machine
  1. When the VM deployment is complete, select Go to resource.
  2. On the left-hand sidebar, select Disks.
  3. On the top bar, select Additional Settings .
  4. Under Encryption settings > Disks to encrypt, select OS and data disks.
  5. Under Encryption settings, choose Select a key vault and key for encryption.
Feb 20, 2024

How do I encrypt an existing disk in VirtualBox? ›

To do this, select your virtual machine in VirtualBox and click on : Configuration. In the settings of your virtual machine, go to : General -> Disk Encryption. Check the "Enable Disk Encryption" box and select the encryption you want to use : AES-XTS256-PLAIN64 or AES-XTS128-PLAIN64.

How can I make my virtual machine more secure? ›

How to Secure a Cloud Virtual Machine: Five Virtualized Security Tips
  1. Secure and Separate Connections. ...
  2. Use Separate Management APIs. ...
  3. Verify VM Components. ...
  4. Isolate Hosted Elements. ...
  5. Regularly Back Up Cloud VMs. ...
  6. Reliable Passwords. ...
  7. Encryption of Everything. ...
  8. Two-Factor Authentication and Role-Based Access.
Mar 1, 2023

How to secure a virtual machine in vmware? ›

Configure Security Settings: Harden your host and the VM's operating system by enabling strong passwords, disabling unnecessary accounts, and applying security patches. Use Anti-VM Detection Countermeasures: Some malware can detect that it's running in a virtual environment.

How do I encrypt a Windows machine? ›

Turn on device encryption
  1. Sign in to Windows with an administrator account (you may have to sign out and back in to switch accounts). For more info, see Create a local or administrator account in Windows.
  2. Select Start > Settings > Privacy & security > Device encryption. ...
  3. If Device encryption is turned off, turn it On.

Should you encrypt VM? ›

Azure VM Encryption:

Encrypting the OS disk ensures that data remains inaccessible without the encryption key, deterring unauthorized access even if the disk is stolen. It adds an additional layer of security by preventing unauthorized access to data even if someone gains access to the VM through RDP.

How do I secure my VirtualBox VM? ›

Securing VM Images: Prioritize the security of your virtual machine images. Regularly update the guest operating systems, applications, and antivirus software within the VMs. Remove unnecessary services, disable guest-to-guest communication, and utilize encryption where applicable.

What is disk encryption in VirtualBox? ›

Oracle VM VirtualBox enables you to transparently encrypt the data stored in hard disk images for the guest. It does not depend on a specific image format to be used. Images which have the data encrypted are not portable between Oracle VM VirtualBox and other virtualization software.

How do I add a disk to my existing VM? ›

On the Virtual Hardware tab, click the Add New Device button. Select Existing Hard Disk from the drop-down menu. The Select File dialog box opens. In the Select File dialog box, expand a datastore, select a Virtual Machine folder, and select the Disk to add.

How do you secure a virtual machine after IT has been deployed? ›

Best Practices
  1. Protect a VM as you would do with a Physical server.
  2. Use hardened templates to Deploy Virtual Machines.
  3. Disable Unnecessary Functions Inside VMs.
  4. Minimize Access to the VMs with principle of least privilege.
  5. Leverage Virtualization-based Security (VBS)
  6. Add a vTPM 2.0.
Oct 14, 2022

What is the biggest risk of using virtual machines? ›

Security Risks: Although VMs are more secure than traditional physical servers, they still come with security risks, such as malware and malicious attacks within the virtual environment. To ensure maximum security, it is important to configure the VMs properly and use advanced security tools.

How do I lock my virtual machine? ›

For each virtual machine do the following: From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> VMware Remote Console Options. Verify the option "Lock the guest operating system when the last remote user disconnects" is checked.

How do I encrypt a virtual machine? ›

Select a virtual machine in the Virtual Machine Library window and click Settings. Under Other in the Settings window, click Encryption. Choose appropriate encryption option and set the encryption password. The password must be eight characters or longer.

How do I protect a VM in VMware? ›

Protect Virtual Machines
  1. Click Workloads > Protection.
  2. Select the VM and click Protect VM. ...
  3. In the Protect VM dialog box, choose the protection tag and its associated protection groups. ...
  4. (Optional) Click Go To VMware Cloud DR to define a protection group in VMware Cloud DR.
  5. Click Assign Protection Tag to protect your VMs.
Dec 11, 2023

How do I put my VM in safe mode? ›

If you are able to load and access your Windows account, the Start menu is working
  1. Click on Windows Start menu > select Settings.
  2. Find System menu > Recovery > under Advanced startup select Restart now. ...
  3. for Safe Mode with Networking if you need to use the Internet.

How do I put a password on my virtual machine? ›

Go to the VM instances page. Click the Windows Server VM to change the password on. On the VM instance details page, in Remote access, click Set Windows password. In the Username field, enter the username to change the password for, or enter a new username to create a new user.

How to tell if a VM is encrypted? ›

Select the VM, then click on Disks under the Settings heading to verify encryption status in the portal. In the chart under Encryption, you'll see if it's enabled.

Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 5903

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.