Security of the Keystore if located on the same virtual machine as the database
Oracle recommends that you place wallet (Keystore) files in local or network directories that are protected by tight file permissions and other security measures.
If someone where to get hold of the virtual hard disks of an Azure VM which includes both the encrypted database and the keystore, can they create a new virtual machine elsewhere (with the virtual hard disk) and have the ability to decrypt the database if auto-login or local auto-login is in use?