What decryption means for a VMware virtual machine
Decrypting a VMware virtual machine means removing the encryption that protects its files so you can access the data inside. VMware offers two main encryption methods: VM encryption, which locks the entire virtual machine and its files, and vSAN encryption, which encrypts storage at the cluster level. If you encrypted a VM yourself or inherited one from someone else, you will need the encryption key or password that was used when encryption was turned on — without it, the files remain locked and unreadable.
The process differs depending on which encryption method was used, what hypervisor version you are running, and whether you still have access to the original encryption credentials. This guide covers the main decryption paths for VMware environments.
Key Takeaways
- VM encryption requires the original encryption key or password; without it, the machine cannot be decrypted.
- vSAN encryption is managed at the cluster level through vCenter, not on individual machines.
- Decryption steps differ between vSphere 6.5 and earlier versions, and vSphere 7.0 and later.
- If you have lost the encryption key, your only option is to contact VMware support or the person who encrypted the machine.
- Decryption removes protection but does not delete the VM; the machine continues to run normally after the process completes.
Decrypting a VM in vSphere 7.0 and later
In vSphere 7.0 and newer versions, VM encryption is managed through vCenter. Open vCenter, find the virtual machine in the inventory, right-click it, and select Edit Settings. Look for the Encryption section in the settings panel. If the VM is encrypted, you will see an option to decrypt it — click Decrypt and confirm your choice.
The system will ask you to provide the encryption key or password that was used when the VM was encrypted. Enter the correct credentials and click OK. The decryption process will begin immediately; the VM does not need to be powered off, though the operation may take several minutes depending on the size of the virtual machine. You can monitor progress in the vCenter Tasks panel at the bottom of the screen.
Once decryption is complete, the VM will no longer be encrypted and the Encryption section in Edit Settings will show no active encryption. The machine remains fully functional and can be used normally.
Decrypting a VM in vSphere 6.5 and earlier
Older versions of vSphere use a different encryption interface. Power off the virtual machine first — encrypted VMs in these versions must be shut down before decryption can begin. Once the VM is off, open vCenter, right-click the machine, and select All vCenter Actions or VM (depending on your vSphere version), then look for Decrypt VM or Remove Encryption.
A dialog box will appear asking for the encryption key or password. This is the same credential that was entered when the VM was first encrypted. Type it in and click Proceed or OK. The decryption process will run in the background; you can check progress in the Recent Tasks panel. After decryption finishes, power the VM back on.
Decrypting vSAN encrypted storage
vSAN encryption works differently from VM encryption because it protects the entire storage cluster, not individual machines. To decrypt vSAN storage, you must have administrative access to vCenter and the vSAN cluster. Open vCenter, navigate to the cluster, and go to Configure > Services > vSAN > Encryption.
You will see the current encryption status and the key management server (KMS) that holds the encryption keys. To disable encryption, click Edit and select Disable Encryption. The system will ask you to confirm; click Yes. vSAN will begin re-encrypting all data with encryption disabled, which can take hours depending on the amount of data stored. During this time, the cluster remains operational and VMs continue to run.
Once the process completes, all new data written to vSAN will be unencrypted. Existing encrypted data will gradually be re-encrypted as it is accessed or moved. This is a cluster-wide change and affects all virtual machines stored on that vSAN cluster.
What to do if you do not have the encryption key
If the VM was encrypted by someone else and you do not have the key or password, decryption is not possible without it. The encryption is designed to be irreversible without the correct credentials — this is a security feature that prevents unauthorized access. Your options are limited: contact the person who encrypted the machine and ask them for the key, or reach out to VMware support with proof of ownership of the VM.
VMware support may be able to help if you can provide documentation showing you own the virtual machine and the host it runs on. However, they cannot decrypt the machine without the original key — they can only help you understand what encryption method was used and what credentials might be needed. If the key is truly lost and no one else has it, the encrypted VM cannot be accessed or decrypted.
Preparing for decryption: backup and testing
Before you decrypt a VM, take a snapshot of the machine while it is encrypted. This gives you a restore point if something goes wrong during decryption. In vCenter, right-click the VM, select Snapshots > Take Snapshot, give it a name like "Before Decryption", and click OK. Wait for the snapshot to complete before proceeding with decryption.
If the VM is critical to your environment, test decryption on a non-production copy first. Clone the encrypted VM to a test environment, decrypt the clone, and verify that the machine boots and runs correctly. This confirms that you have the correct encryption key and that the decryption process will work as expected on your production machine.
Common problems during decryption
The most common issue is entering an incorrect encryption key or password. If decryption fails, vCenter will display an error message saying the key is invalid. Double-check the key for typos — encryption keys are case-sensitive and must match exactly. If you are unsure about the key, contact whoever encrypted the machine.
Another issue is attempting to decrypt a VM that is not actually encrypted. If you right-click a VM and do not see a decrypt option, the machine is not encrypted and there is nothing to decrypt. This sometimes happens when someone thinks a VM is encrypted but encryption was never enabled, or when encryption was already removed.
If decryption hangs or appears to freeze, check the vCenter Tasks panel to see if the operation is still running. Decryption of large VMs can take a long time — wait at least 30 minutes before assuming the process has failed. If the task genuinely appears stuck, you can cancel it and try again, though this may leave the VM in an inconsistent state. Contact VMware support if this happens.
Frequently Asked Questions
Can I decrypt a VM while it is running?
In vSphere 7.0 and later, yes — the VM can stay powered on during decryption. In vSphere 6.5 and earlier, the VM must be powered off. Check your vSphere version in vCenter under Home > About to see which process applies to you.
Will decryption delete my data?
No. Decryption removes the encryption layer but does not delete or modify any files inside the VM. All data remains intact and the machine will function normally after decryption is complete.
What happens if I lose the encryption key?
The VM cannot be decrypted without the original key. Contact the person who encrypted it or VMware support. If the key is truly lost and no backup exists, the VM will remain encrypted and inaccessible.
Can I re-encrypt a VM after I decrypt it?
Yes. Once a VM is decrypted, you can encrypt it again at any time using the same process you used originally. You will create a new encryption key or password for the re-encryption.
Does decryption affect VM performance?
No. Decryption is a one-time operation that removes encryption; it does not change how the VM runs afterward. Performance will be the same before and after decryption.