Skip to main content
Question

Restoring Encrypted Azure VM

  • January 22, 2025
  • 2 replies
  • 34 views

I’m having issues doing a restore of an encrypted Azure VM

We can backup the Azure VMs encrypted and non encrypted. We can restore non encrypted VMs. But not with encrypted VMs.

I have a support ticket but so far I’m not happy with the support I’m getting.

I was told to create a new Azure KV which we did but still having the issue

I was told to add the key vault entry in the Commvault → Control Panel → Key Management Servers… still not working and also is this necessary? I’ve never found documentation pointing to this when doing Azure VM restore.

In the access node logs for vsrst.log

17388 470c  01/22 10:49:51 3122047 VSRstCoordinator::SummarizeVMList() - VM xxxx-restore3    --> STARTED                     100%
17388 1dc8  01/22 10:49:52 3122047 Checking for keyvault [kv-xxxxx] in location [australia]
17388 1dc8  01/22 10:49:56 3122047 InitEncryptionSettingsForKey() - Key vault is not found in destination region. Creating a keyvault with name [kv-xxxxx]
17388 1dc8  01/22 10:49:56 3122047 AzureResourceManagement.CreateOrUpdateKeyVault() - MSI authentication is enabled. Keyvault cannot be created

Does Commvault needs to create a new KeyVault? Commvault cannot use the exisitng keyvault which we have given access to do backups?

This is a restore on the same subscription and same region its just restoring to a different name (out of place)

2 replies

Forum|alt.badge.img+7

Hi ​@Rommel ,

Good day!

Hope the question has been answered on the support case.

Does Commvault needs to create a new KeyVault? Commvault cannot use the exisitng keyvault which we have given access to do backups?

This is not required we can use the exisitng ones

Regards,

Sureshkumar S


Onno van den Berg
Commvault Certified Expert
Forum|alt.badge.img+19
  • Commvault Certified Expert
  • 1237 replies
  • January 29, 2025

Does the account that is used by Commvault has enough permissions to be able to pull the keys from Key Vault? Additionally what version are you running? 

https://documentation.commvault.com/2024e/expert/adding_permissions_to_back_up_azure_vms_encrypted_with_azure_key_vault.html 

Looks like your identity is not able to create the entry in Key Vault.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings