RSA or RSA-HSM key of 2048, 3072 or 4096 bits that you keep in Key Vault or Managed HSM to wrap a storage account's encryption key. You can switch it on later, except for tables and queues, whose CMK support must be chosen at creation.
Also called CMK.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Customer-managed keys in context, with comparison tables and the common traps.
Terms in this definition
- RSA
Public-key encryption algorithm. For storage customer-managed keys, RSA and RSA-HSM keys of 2048, 3072 or 4096 bits are accepted; a SQL TDE protector cannot use 4096 bits.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - BITS
A Windows service for downloads. Delivery Optimization hands downloads to it in Bypass mode (100), a mode now deprecated for Windows 11 that can cause failures with error 0x80d03002.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Managed HSM
Pool of FIPS-validated hardware security modules in Azure Key Vault, dedicated to a single tenant, able to store customer-managed encryption keys such as a TDE protector.
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- SWITCH
Checks one expression against several candidate values, returning whichever result pairs with the match (or a fallback otherwise). Writing SWITCH ( TRUE (), ... ) avoids nested IF chains: whichever condition is first true wins.
Related terms
- 3DES
Older symmetric block cipher (Triple DES) regarded today as weak. Storage customer-managed keys cannot use it as a key type.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Microsoft Defender for Cloud Servers Scanner Resource Provider
First-party app (ID 0c7668b5-3260-4ad0-9f53-34ed54fa19b2) behind agentless scanning. Where disks use a CMK, it requires the Key Vault Crypto Service Encryption User role or the Get, Wrap Key and Unwrap Key permissions.
- Microsoft-managed keys
The keys Azure uses by default to encrypt data at rest, which it creates, stores, rotates and backs up for you free of charge. If you must control the keys yourself, you use customer-managed keys held in Key Vault or Managed HSM instead.
- Sovereign Landing Zone
Builds on the Azure platform landing zone's design principles and library, adding sovereignty measures such as keeping data in a region, customer-managed keys and confidential computing. It is not meant to replace an Azure landing zone already in place.
- wrapKey / unwrapKey
Operations in Key Vault for encrypting and decrypting one key with another. Together with get, they are the access-policy permissions required by the identity behind a CMK or TDE protector.