Skip to content
Compute and web des

Disk encryption set naming convention

The CAF abbreviation for Disk encryption set is des. Names can be 1 to 80 characters long and allow alphanumerics, hyphens and underscores. The name must be unique within the resource group.

Naming rules

CAF abbreviation des
Length 1 to 80 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9), hyphens, underscores
Scope of uniqueness Unique within the resource group
CAF pattern des-{workload}-{environment}-{region}-{instance}

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Compute and web resources

Web apps and Function apps share the same global namespace, both become a subdomain of azurewebsites.net, so a name you want for a function app might already be taken by a web app someone else owns, and the reverse is just as possible. It is worth checking availability before committing to a name here even though the two are different resource types in the portal. Static Web Apps get their own globally unique default hostname too.

Disks and snapshots multiply fast around a single VM, an OS disk, one or more data disks, and snapshots of each, so name them to point back unambiguously to the parent VM, with a purpose suffix like os or data-01 rather than a bare number. A common mistake is treating a VM name and its Windows computer name as one field, they are governed by different length limits (64 characters versus 15) and can validly diverge once truncation kicks in.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production des-payments-prod-eus-001 25/80
Web app, development des-webapp-dev-weu-002 22/80
Analytics with company prefix des-contoso-analytics-stage-uks-001 35/80

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  disk_encryption_set_name = "des-${var.workload}-${var.environment}-${var.region}-001"
}
Bicep
var diskEncryptionSetName = 'des-${workload}-${environment}-${region}-001'

Generate Disk encryption set names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Compute and web resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.