Permissions
The Azure CIS v2.0.0 - Section 7 - Virtual Machines policy pack requires 4 permissions:
microsoft.compute/diskencryptionsets/read
microsoft.compute/disks/write
microsoft.compute/virtualmachines/deallocate/action
microsoft.compute/virtualmachines/delete