If you specified a Key Encryption Key (KEK) when you created the Cloud VM Set, you can revoke access to all of the VMs in the Cloud VM Set by revoking access to the KEK. When you do so, Cryptographic Security Platform Vault for VM Encryption immediately deactivates and detaches all encrypted disks for all VMs in the Cloud VM Set regardless of the KEK expiration date.

The Revoke KEK action can be performed with base64-encoded KEK.

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Select the Cloud VM Set for which you want to revoke access.
  4. Select Actions > Revoke Key Encryption Key.
  5. Click Revoke.
  6. To verify that the KEK was revoked, click on the Key Encryption Key tab and look at the Key Encryption Key State field. While the operation is proceeding, the state is REVOKE_PENDING. When the process is finished, the state changes to REVOKED.

While the key is revoked, you will not be able to add a new VM to the Cloud VM Set or access, encrypt, or decrypt any of the existing VMs in the set. These operations are only available when the KEK state is ACTIVE.

To restore access to the VMs, select the Cloud VM Set then select Actions > Unrevoke Key Encryption Key. Cryptographic Security Platform Vault for VM Encryption restores access to the VMs as long as the KEK has not expired.