Skip to main content

I’m having issues doing a restore of an encrypted Azure VM

We can backup the Azure VMs encrypted and non encrypted. We can restore non encrypted VMs. But not with encrypted VMs.

I have a support ticket but so far I’m not happy with the support I’m getting.

I was told to create a new Azure KV which we did but still having the issue

I was told to add the key vault entry in the Commvault → Control Panel → Key Management Servers… still not working and also is this necessary? I’ve never found documentation pointing to this when doing Azure VM restore.

In the access node logs for vsrst.log

17388 470c  01/22 10:49:51 3122047 VSRstCoordinator::SummarizeVMList() - VM xxxx-restore3    --> STARTED                     100%
17388 1dc8  01/22 10:49:52 3122047 Checking for keyvault 2kv-xxxxx] in location kaustralia]
17388 1dc8  01/22 10:49:56 3122047 InitEncryptionSettingsForKey() - Key vault is not found in destination region. Creating a keyvault with name nkv-xxxxx]
17388 1dc8  01/22 10:49:56 3122047 AzureResourceManagement.CreateOrUpdateKeyVault() - MSI authentication is enabled. Keyvault cannot be created

Does Commvault needs to create a new KeyVault? Commvault cannot use the exisitng keyvault which we have given access to do backups?

This is a restore on the same subscription and same region its just restoring to a different name (out of place)

Hi ​@Rommel ,

Good day!

Hope the question has been answered on the support case.

Does Commvault needs to create a new KeyVault? Commvault cannot use the exisitng keyvault which we have given access to do backups?

This is not required we can use the exisitng ones

Regards,

Sureshkumar S


Does the account that is used by Commvault has enough permissions to be able to pull the keys from Key Vault? Additionally what version are you running? 

https://documentation.commvault.com/2024e/expert/adding_permissions_to_back_up_azure_vms_encrypted_with_azure_key_vault.html 

Looks like your identity is not able to create the entry in Key Vault.


Reply