Permissions
The Azure CIS v2.0.0 - Section 7 - Virtual Machines policy pack requires 4 permissions:
microsoft.compute/diskencryptionsets/readmicrosoft.compute/disks/writemicrosoft.compute/virtualmachines/deallocate/actionmicrosoft.compute/virtualmachines/delete