6.5.1

Table Of Contents
3 Right-click the virtual machine, and follow the prompts to create the clone of an encrypted virtual
machine.
Option Action
Select a name and folder Specify a name and target location for the clone.
Select a compute resource Specify an object for which you have privileges to create encrypted virtual
machines. See Prerequisites and Required Privileges for Encryption Tasks.
Select storage Make a selection in the Select virtual disk format menu and select a datastore.
You cannot change the storage policy as part of the clone operation.
Select clone options Select clone options, as discussed in the vSphere Virtual Machine Administration
documentation.
Ready to complete Review the information and click Finish.
Encrypt an Existing Virtual Machine or Virtual Disk
You can encrypt an existing virtual machine or virtual disk by changing its storage policy. You can encrypt
virtual disks only for encrypted virtual machines.
You cannot encrypt a virtual machine by using the Edit Settings menu. You can encrypt virtual disks of
an encrypted virtual machine by using the Edit Settings menu.
Prerequisites
n
Establish a trusted connection with the KMS and select a default KMS.
n
Create an encryption storage policy.
n
Ensure that the virtual machine is powered off.
n
Verify that you have the required privileges:
n
Cryptographic operations.Encrypt new
n
If the host encryption mode is not Enabled, you also need Cryptographic operations.Register
host.
Procedure
1 Connect to vCenter Server by using the vSphere Web Client.
2 Right-click the virtual machine that you want to change and select VM Policies > Edit VM Storage
Policies.
You can set the storage policy for the virtual machine files, represented by VM home, and the storage
policy for virtual disks.
3 Select the storage policy that you want to use from the drop-down menu.
n
To encrypt the VM and its hard disks, select an encryption storage policy and click Apply to all.
n
To encrypt the VM but not the virtual disks, select the encryption storage policy for VM Home and
other storage policies for the virtual disks, and click Apply.
You cannot encrypt the virtual disk of an unencrypted VM.
vSphere Security
VMware, Inc. 167