Applies to: Enterprise and Audit
Licence requirement
Virtual-machine use requires DriveErase Enterprise or Audit.
Sanitization scope
Inside a virtual machine, DriveErase operates only on the storage device presented to the guest. That device can be a virtual disk file, a logical volume, a passed-through physical disk, or another hypervisor-managed storage object.
A guest-level result does not automatically cover:
- Hypervisor snapshots;
- Template or clone files;
- Host backups;
- Storage-array snapshots;
- Replicas;
- Thin-provisioning pools;
- Deduplicated blocks;
- Cache tiers;
- The physical media supporting the virtual disk.
Each external copy requires separate lifecycle controls.
Typical method availability
Virtual disks normally support host overwrite through the guest-visible logical range. Device-firmware commands are generally unavailable unless the hypervisor provides supported direct device passthrough and the complete command path remains accessible in the Privileged Execution Environment.
Even with passthrough, validate the target identity carefully and confirm that the virtual machine cannot access unrelated host storage.
Snapshot and backup controls
Before sanitization:
- Identify and remove or separately sanitize approved snapshots and clones;
- Review backup retention and immutability requirements;
- Stop replication where permitted;
- Record the virtual-disk identifier and backing-store location;
- Confirm that the guest’s system disk is not the intended target;
- Obtain hypervisor and storage-team approval.
