Answered by:
Azure VM with Bit-locker now fails to decrypt due to Azure Key Vault internal error?

Question
-
I have an Azure Key Vault physical HSM and 3 VMs deployed to an ARM resource group within a region. 2 VMs are Win Server 2012 with BitLocker extension encrypted via Key Vault. 1 VM is linux (not encrypted) with no problem. Windows machines starting and stopping daily and working fine until yesterday they failed to start. No feedback from the portal but on Powershell gives the error:
"InnerError": null,
"Code": "DiskEncryptionInternalError",
"Message": "Unknown error encountered when retrieving https............. from the Key Vault.",
Application and credentials & key vault permissions remain current. Azure Key Vault service for the region is showing as "healthy". I'm awaiting support request response. Any ideas would be appreciated. I hope Azure can save my machines.
Monday, February 1, 2016 12:59 AM
Answers
-
Hi Paul -
I see that the question is being addressed in another thread over at http://stackoverflow.com/questions/35121437/azure-vm-with-bit-locker-now-fails-to-decrypt-due-to-azure-key-vault-internal-er
We'll continue to engage there.
Thanks!
Learn more about Azure Security at the Azure Security Team blog
- Marked as answer by Thomas W Shinder - MSFTMicrosoft employee Tuesday, February 2, 2016 2:37 PM
Monday, February 1, 2016 3:25 PM
All replies
-
Hi Paul -
Not sure what's happening here. Let me find someone who can help you out.
Thanks!
Tom
Learn more about Azure Security at the Azure Security Team blog
Monday, February 1, 2016 3:13 PM -
Hi Paul,
I believe you reported the same issue on stackoverflow.com site. Aravind responded you requesting to start a thread with the email provided. Can you please take a look at the response on stackoverflow.com site.
Thanks, Devendra
Monday, February 1, 2016 3:20 PM -
Hi Paul -
I see that the question is being addressed in another thread over at http://stackoverflow.com/questions/35121437/azure-vm-with-bit-locker-now-fails-to-decrypt-due-to-azure-key-vault-internal-er
We'll continue to engage there.
Thanks!
Learn more about Azure Security at the Azure Security Team blog
- Marked as answer by Thomas W Shinder - MSFTMicrosoft employee Tuesday, February 2, 2016 2:37 PM
Monday, February 1, 2016 3:25 PM -
Hi Tom,
Thanks for the attention. Sorry about the double up. Will continue with Stack Exchange. FYI, Aravind asked for and I have sent the full error text & relevant subscription ID so he can check the logs to see what happened.
Regards, P
Tuesday, February 2, 2016 12:10 AM -
Hi Paul -
No problem! Hope we can help get this resolved for you.
Tom
Learn more about Azure Security at the Azure Security Team blog
Tuesday, February 2, 2016 1:15 AM