1 - Register the Microsoft.compute encryption provider feature. 2 - Create a key in KV1 and configure a disk encryption set. 3 - Deploy the virtual machines and set Encryption at host to Yes. Reference: https://docs.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal