If you revoke access to a disk, it will be deactivated and detached on the next heartbeat. Any attempt to attach the disk using hcl attach will fail with the message stating that the key could not be fetched because the disk is not active.

If this is a Windows boot disk, the VM will be unable to boot. If this is a standard Windows disk, the associated drive will no longer be available through Windows Explorer or to any applications running on the Windows server. If this is a Linux disk, the filesystem will be unmounted and it will likewise be unavailable to any applications running on the server.

  1. Log into the Cryptographic Security Platform Vault for VM Encryption webGUI using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Click the VMs tab and select the VM you want to work with from the list.
  4. Click the Expand button (>) at the end of the row to access the details for the specific VM.
  5. Click the Encrypted Disks tab and select the disk that you want to revoke.
  6. Select Revoke Disk Access from the VM-specific Actions menu.
  7. Click Proceed at the prompt to confirm the revoke request. Cryptographic Security Platform Vault changes the disk state to Revoked/Attached until the action completes, at which time it changes the state to Detached.