Label-based encryption requiring two keys, one kept in Azure and one in the organisation's own DKE service, so Microsoft is unable to decrypt the data. Because services such as search, eDiscovery and Copilot cannot read protected content, it suits only a small amount of highly sensitive data.
Also called DKE.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Double Key Encryption in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- eDiscovery
Locating, holding, reviewing and exporting electronic information to serve as evidence in investigations or lawsuits. Microsoft Purview covers Teams, Exchange, OneDrive, SharePoint and other sources, and E5 unlocks extra premium capabilities.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- Azure Rights Management
The service that does the actual encrypting behind sensitivity labels, message encryption and DKE in Purview Information Protection, attaching usage rights to protected content. Newer tenants get it switched on automatically; older ones turn it on with PowerShell.
- HYOK
An on-premises-held key used for encrypting content. Co-authoring, search, eDiscovery and DLP can't work on content protected like this, and Microsoft recommends Double Key Encryption as the replacement.