To back up Azure VMs that are encrypted with Azure Key Vault, you must provide the appropriate permissions for accessing the key vault.
Support
Only VMs that are encrypted with Azure Key Vault for management of secrets (token and password information) and keys (algorithm information) are supported.
Procedure
-
Log on to the Microsoft Azure portal.
-
From the left-side navigation pane, click All services.
-
From the All services window pane, scroll to the SECURITY section, and click on Key vaults.
The list of key vaults associated with your subscriptions appears.
-
For each key vault associated with the subscription where the encrypted guest VMs, do the following:
-
From the list of key vaults, click the key vault.
-
From the settings menu, select Access Policies, and then click Add New.
-
Click Add New.
-
From the Configure from template list, select Key & Secret Management.
All operation permissions for Key and Secret Management are selected by default. However, you only need to select the following permissions:
-
For Key permissions, select Get, Backup, Recover, and Restore.
-
For Secret permissions, select Get, Backup, Recover, and Restore.
-
-
For Select principal, search for either the VM or the Azure AD application (depending on which method was used for when the workload was added to Commvault), and then click Select.
-
Click OK.
-
Click Save.
-