This document discusses security of disks in Azure and encryption options. It describes Azure Disk Encryption (ADE) which uses a key vault to encrypt virtual machine disks. The prerequisites for ADE are to create a key vault, set access policies, and store encryption keys in the vault. It provides commands to create the key vault, set policies, encrypt existing disks on Windows and Linux VMs, view encryption status, decrypt disks, and automate deployment using templates.