Azure VM加密脚本未弹出aadAppName输入请求的问题求助
Hey there, let's work through this disk encryption problem you're hitting while getting your VM ready to be a domain controller. It's frustrating when the script doesn't prompt for input like it's supposed to—here are some actionable fixes to get you back on track:
1. Verify Your Script's Execution Environment
First off, make sure you're running the script in an interactive, elevated PowerShell session:
- If you're using Azure Cloud Shell, sometimes non-interactive modes can suppress
Read-Hostprompts. Try launching a local PowerShell window as Administrator instead. - Avoid running the script in background tasks, automation pipelines, or non-interactive terminals—these environments won't display input prompts.
2. Manually Retrieve Required Parameters (Bypass the Script Prompt)
Since the script isn't prompting for aadAppName, you can create the AAD application and gather all needed values manually:
- Log into your Azure account:
Connect-AzAccount - Create a new AAD application (replace
YourDCEncryptionAppwith your preferred name):$aadApp = New-AzADApplication -DisplayName "YourDCEncryptionApp" -HomePage "https://contoso.com/dc-encryption" -IdentifierUris "https://contoso.com/dc-encryption" - Create a service principal for the app:
$sp = New-AzADServicePrincipal -ApplicationId $aadApp.ApplicationId - Generate a client secret (valid for 1 year here—adjust the end date as needed):
$clientSecret = New-AzADAppCredential -ApplicationId $aadApp.ApplicationId -EndDate (Get-Date).AddYears(1) - Pull your key vault details:
$kv = Get-AzKeyVault -VaultName "YourKeyVaultName" -ResourceGroupName "YourResourceGroup" - Now you have all the values you need:
aadClientID:$aadApp.ApplicationIdaadClientSecret:$clientSecret.SecretTextdiskEncryptionKeyVaultUrl:$kv.VaultUrikeyVaultResourceId:$kv.ResourceId
3. Fix the Script's Input Logic
If you want to stick with the original script, try modifying it to skip the prompt:
- Add a predefined
$aadAppNamevariable at the top of the script, like:$aadAppName = "YourDCEncryptionApp" # Use the name you chose earlier - This should force the script to use this app name (create it if it doesn't exist) without waiting for user input.
4. DC-Specific Encryption Notes
Since this VM is destined to be a domain controller, keep these in mind:
- Encrypt before promoting to DC: It's safer to complete disk encryption before you set up AD DS on the VM. Encrypting a running DC can lead to issues with AD database integrity.
- Set key vault permissions: Make sure the service principal you created has the
Disk Encryption Contributorrole on your key vault, or theKey Vault Crypto Officerpermission, to access encryption keys.
Once you have all the parameters, you can run the encryption command directly to test:
Set-AzVMDiskEncryptionExtension -ResourceGroupName "YourResourceGroup" -VMName "YourVMName" -AadClientID $aadApp.ApplicationId -AadClientSecret $clientSecret.SecretText -DiskEncryptionKeyVaultUrl $kv.VaultUri -DiskEncryptionKeyVaultId $kv.ResourceId
内容的提问来源于stack exchange,提问作者Giles

