Azure service holding secrets, keys and certificates. If the region has a paired region in the same geography, contents replicate to it, and during a best-effort failover initiated by Microsoft the vault can only be read.
Also called Key Vault, Key Vault.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-103AI-200SC-900AZ-400ALZ
Each book explains Azure Key Vault in context, with comparison tables and the common traps.
Terms in this definition
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
- Paired region
A region linked with another in the same geography so updates are rolled out in sequence and recovery is prioritised. It is the typical disaster recovery target, though pairing does not trigger failover automatically.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- AzureKeyVault (service tag)
Service tag, usable outbound and optionally regional, that represents the IP ranges of Azure Key Vault.
- BYOC
Option for HTTPS on a Front Door custom domain in which your own certificate sits in Azure Key Vault, read through a managed identity or registered service principal; direct upload isn't possible and the chain must come from a Microsoft Trusted CA.
- Column master key
Protects the column encryption keys in Always Encrypted. It never lives in the database itself but in Azure Key Vault or the Windows certificate store, and client apps need permission to use it.
- CSI
Short for Container Storage Interface, the Kubernetes standard for storage drivers. Using the Azure Key Vault provider, the Secrets Store CSI Driver gives AKS pods a mounted volume containing Key Vault certificates, keys and secrets.
- Disk encryption set
Lets you choose your own key, held in Azure Key Vault or a Managed HSM, for the server-side encryption Azure applies to managed disks; each disk is pointed at this resource.
- EKM
A provider model that lets SQL Server use symmetric or asymmetric keys kept somewhere else, such as Azure Key Vault. That is what makes a customer-managed key possible as the TDE protector.
- KMS
Legacy AKS plug-in using an Azure Key Vault key to encrypt Kubernetes Secrets at rest in etcd. On Kubernetes 1.33 onwards, Microsoft Learn points to the newer KMS data encryption experience instead.
- Managed HSM
Pool of FIPS-validated hardware security modules in Azure Key Vault, dedicated to a single tenant, able to store customer-managed encryption keys such as a TDE protector.