Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Customer-managed keys (CMKs) are a key management control model in which you own and manage the key encryption key (KEK) in your own Azure Key Vault or Azure Key Vault Managed HSM instance. Azure services use your KEK to wrap and unwrap their data encryption keys through envelope encryption. For HSM-protected keys, use Azure Key Vault Premium tier or Azure Key Vault Managed HSM.
The following services support server-side encryption with customer-managed keys. For implementation details, see the service-specific documentation or the service's Microsoft Cloud Security Benchmark: security baseline (section DP-5).
AI and machine learning
Analytics
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Azure Data Explorer | Yes | Configure customer-managed keys (CMK) in Azure Data Explorer | |
| Azure Data Factory | Yes | Yes | Encryption with customer-managed keys for Azure Data Factory |
| Azure Databricks | Yes | Yes | Customer-managed keys for managed services |
| Azure HDInsight | Yes | Azure HDInsight double encryption for data at rest | |
| Azure Monitor Application Insights | Yes | Customer-managed keys in Azure Monitor | |
| Azure Monitor Log Analytics | Yes | Yes | Customer-managed keys in Azure Monitor |
| Azure Stream Analytics | Yes* | Yes | Data protection in Azure Stream Analytics |
| Azure Synapse Analytics | Yes (RSA 3072-bit) | Yes | Configure encryption at rest with customer-managed keys |
Containers
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Azure Kubernetes Service | Yes | Yes | Enable host encryption on your AKS cluster nodes |
| Container Instances | Yes | Encrypt data with a customer-managed key | |
| Container Registry | Yes | Encrypt container images with a customer-managed key |
Compute
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| App Service | Yes* | Yes | Configure customer-managed keys for App Service |
| Azure Functions | Yes* | Yes | Configure customer-managed keys for Azure Functions |
| Azure Managed Applications | Yes* | Yes | Azure managed applications overview |
| Azure portal | Yes* | Yes | Security in the Azure portal |
| Virtual Machine Scale Set | Yes | Yes | Overview of managed disk encryption options |
| Virtual Machines | Yes | Yes | Overview of managed disk encryption options |
Databases
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Azure Cosmos DB | Yes | Yes | Configure customer-managed keys using Azure Key Vault |
| Azure Database for MySQL - Flexible Server | Yes | Yes | Data encryption with customer-managed keys in Azure Database for MySQL - Flexible Server |
| Azure Database for PostgreSQL - Flexible Server | Yes | Yes | Data encryption with customer-managed keys in Azure Database for PostgreSQL - Flexible Server |
| Azure SQL Database | Yes (RSA 3072-bit) | Yes | Bring your own key (BYOK) support for Transparent Data Encryption (TDE) |
| Azure SQL Managed Instance | Yes (RSA 3072-bit) | Yes | Bring your own key (BYOK) support for Transparent Data Encryption (TDE) |
| SQL Server on Azure VM | Yes | Configure Azure Key Vault integration for SQL Server on Azure VMs | |
| SQL Server on Virtual Machines | Yes | Transparent data encryption for SQL Server on Azure VM | |
| Table Storage | Yes | Yes | Customer-managed keys for Azure Storage encryption |
Integration
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Azure Fluid Relay | Yes | Yes | Customer-managed keys for Azure Fluid Relay |
| Event Hubs | Yes | Yes | Configure customer-managed keys for encryption |
| Logic Apps | Yes | ||
| Service Bus | Yes | Yes | Configure customer-managed keys for encryption |
IoT services
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| IoT Hub Device Provisioning | Yes |
Management and governance
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| App Configuration | Yes | Use customer-managed keys to encrypt data | |
| Automation | Yes | Encryption of automation assets | |
| Azure Migrate | Yes | Tutorial: Migrate VMware VMs to Azure | |
| Azure Monitor | Yes | Yes | Customer-managed keys in Azure Monitor |
Security
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Azure Information Protection | Yes | Yes | How are the Azure Rights Management cryptographic keys managed and secured? |
| Microsoft Defender for Cloud | Yes | Yes | Customer-managed keys in Azure Monitor |
| Microsoft Sentinel | Yes | Yes | Encryption at rest in Microsoft Sentinel |
Storage
Other
| Product, feature, or service | Key Vault | Managed HSM | Documentation |
|---|---|---|---|
| Universal Print | Yes | Yes | Data encryption in Universal Print |
Caveats
* This service supports storing data in your own Azure Key Vault, storage account, or other data-persisting service that already supports server-side encryption with a customer-managed key.
** Any transient data stored temporarily on disk such as page files or swap files are encrypted with a Microsoft key (all tiers) or a customer-managed key (using the Enterprise and Enterprise Flash tiers).