Optional Key Vault RSA key whose job is to wrap, or encrypt, a second encryption key such as the secret used by Azure Disk Encryption. Its versioned key URL identifies it.
Also called KEK.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key encryption key in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- RSA
Public-key encryption algorithm. For storage customer-managed keys, RSA and RSA-HSM keys of 2048, 3072 or 4096 bits are accepted; a SQL TDE protector cannot use 4096 bits.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Job
A sequence of steps executed together on one agent or runner, or on the server for agentless work. While running, each occupies one of your parallel jobs.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
- URL
The web address of a resource, on which URL-based routing relies.
Related terms
- Deep recrypt
Swapping both keys (KEK and DEK) on an already-encrypted VM, which needs it powered off and with no snapshots. Changing just the KEK is called a shallow recrypt.
- Shallow recrypt
Changing only the KEK that protects a VM's keys, which can happen with the VM running. Changing the data encryption key too is a deep recrypt, for which the VM has to be off.
- vSphere Virtual Machine Encryption
ESX encrypts a VM's files and disks with a per-VM XTS-AES-256 data key, which a key encryption key from the key provider then wraps.