You can use the CLI to perform a shallow rekey of an encrypted virtual machine. You might perform a rekey of an encrypted virtual machine for business or compliance reasons.
A shallow key (also called recrypt) replaces only the Key Encryption Key (KEK). You do not need to power off the encrypted virtual machine to perform a shallow rekey. If you need to replace both the Disk Encryption Key (DEK) and the KEK, you must perform a deep rekey.
This task shows how to perform a shallow rekey on an encrypted virtual machine using the currently assigned key provider.
For more conceptual information, see How Do You Recrypt (Rekey) an Encrypted Virtual Machine.
Prerequisites
Required privilege:
Note: Virtual machines configured with IDE controllers must be powered off to perform a shallow rekey operation.