6.7

Table Of Contents
d To decrypt a virtual disk but not the virtual machine, deselect the disk.
e Click OK.
5 (Optional) You can change the Encrypted vMotion setting.
a Right-click the virtual machine and click Edit Settings.
b Click VM Options, and open Encryption.
c Set the Encrypted vMotion value.
Change the Encryption Policy for Virtual Disks
When you create an encrypted virtual machine from the vSphere Web Client, any virtual disks that you
add during virtual machine creation are encrypted. You can decrypt virtual disks that are encrypted by
using the Edit VM Storage Policies option.
Note An encrypted virtual machine can have virtual disks that are not encrypted. However, an
unencrypted virtual machine cannot have encrypted virtual disks.
See Virtual Disk Encryption.
This task describes how to change the encryption policy using storage policies. You can use either the
vSphere Client (HTML5-based client) or the vSphere Web Client. You can also use the Edit Settings
menu to make this change.
Prerequisites
n
You must have the Cryptographic operations.Manage encryption policies privilege.
n
Ensure that the virtual machine is powered off.
Procedure
1 Connect to vCenter Server by using either the vSphere Client (HTML5-based client) or the
vSphere Web Client.
2 Right-click the virtual machine and select VM Policies > Edit VM Storage Policies .
3 Change the storage policy.
n
vSphere Client (HTML5-based client):
n
To change the storage police for the VM and its hard disks, select an encryption storage
policy and click OK.
n
To encrypt the VM but not the virtual disks, toggle on Configure per disk, select the
encryption storage policy for VM Home and other storage policies for the virtual disks, and
click OK.
n
vSphere Web Client:
n
To change the storage policy for the VM and its hard disks, select an encryption storage
policy and click Apply to all.
vSphere Security
VMware, Inc. 169