Supported today
Not supported, with reasons
A VM that falls into one of these categories is skipped with the reason above shown against it, never silently dropped from results.
Google-managed projects are excluded from Plerion entirely, not just from workload scanning. See Projects Plerion does not scan.
CMEK-encrypted disks: supported, encryption-stripped
Workload scanning does scan VMs backed by a customer-managed encryption key (CMEK). The snapshot it takes inherits your key, but the scan disk created from that snapshot in the scanning project carries Google-managed encryption instead of your key: Plerion isn’t granted, and doesn’t need, access to decrypt with your CMEK key to create it. This means CMEK-backed VMs get full scan coverage, with one disclosed trade-off: for the short window the scan disk exists, its confidentiality boundary is Google-managed rather than customer-managed. See How scanning works for the full mechanics. Tagging a projectPlerionAccess: Denied (see the GCP integration overview) removes Plerion’s own Cloud KMS access to that project. It is a key-access control, not a scanning one: project selection is what decides which projects Plerion scans.
To stop scanning a project, exclude it from the organization integration’s project selection under Manage projects.