6.7

Table Of Contents
n
Verify that you have the required privileges:
n
Cryptographic operations.Encrypt new
n
If the host encryption mode is not Enabled, you also need Cryptographic operations.Register
host.
Procedure
1 Connect to vCenter Server by using either the vSphere Client (HTML5-based client) or the
vSphere Web Client.
2 Right-click the virtual machine that you want to change and select VM Policies > Edit VM Storage
Policies.
You can set the storage policy for the virtual machine files, represented by VM home, and the storage
policy for virtual disks.
3 Select the storage policy.
n
vSphere Client (HTML5-based client):
n
To encrypt the VM and its hard disks, select an encryption storage policy and click OK.
n
To encrypt the VM but not the virtual disks, toggle on Configure per disk, select the
encryption storage policy for VM Home and other storage policies for the virtual disks, and
click OK.
n
vSphere Web Client:
n
To encrypt the VM and its hard disks, select an encryption storage policy and click Apply to
all.
n
To encrypt the VM but not the virtual disks, select the encryption storage policy for VM Home
and other storage policies for the virtual disks, and click Apply.
You cannot encrypt the virtual disk of an unencrypted VM.
4 If you prefer, you can encrypt the virtual machine, or both virtual machine and disks, from the Edit
Settings menu in the vSphere Client.
a Right-click the virtual machine and select Edit Settings.
b Select the VM Options tab, and open Encryption. Choose an encryption policy. If you deselect
all disks, only the VM home is encrypted.
c Click OK.
Decrypt an Encrypted Virtual Machine or Virtual Disk
You can decrypt a virtual machine, its disks, or both, by changing the storage policy.
This task describes how to decrypt an encrypted virtual machine using either the vSphere Client (HTML5-
based client) or the vSphere Web Client.
vSphere Security
VMware, Inc. 167