Automatic Data Encryptiononly works for Linux devices that are not mounted. Therefore, you cannot useAutomatic Data Encryptionto encrypt Linux system devices such as/root,swap, or/home.
Automatic Data Encryptionfor Linux works with partitioned disks only.
If you want to encrypt a Windows boot drive, you must install theEntrust Bootloaderoption with thePolicy Agenton that VM. Auto encryption on the boot drive will fail if theBootloaderis not installed. For details, seeWindows Boot Drive Encryption.
If you change theAutomatic Data Encryption Policyfor aCloud VM Set, you can choose whether to propagate the changes to the VMs already registered with the set. If you do so, any changes you made on the individual VMs will be overwritten by the settings in theCloud VM Set. All customizations on the individual VMs will be lost.
If you change theAutomatic Data Encryption Policyto include a device that was not included before,Cryptographic Security Platform Vaultautomatically schedules a task to encrypt the newly- added device.
After a device has been encrypted (either manually or through anAutomatic Data Encryption Policy),Cryptographic Security Platform Vaultwillnotautomatically decrypt it, even if you change theAutomatic Data Encryption Policytoexcludethat device. Once encrypted, all devices must be decrypted manually.
If you try to decrypt a device that is specified asIncludedin theAutomatic Data Encryption Policy, the decryption task will fail. You must first remove the device from theAutomatic Data Encryption Policybefore you can decrypt it. If you remove the device from the policy at the VM-level, that device can only be decrypted on that VM. If you remove the device from the policy on theCloud VM Setlevel and you propagate the changes from theCloud VM Setto the registered VMs, then you can decrypt that device on any registered VM.