CMK Encryption for Azure Storage Accounts (2024)

CMK Encryption for Azure Storage Accounts (1)

Vivekanand Rapaka

Posted on

CMK Encryption for Azure Storage Accounts (2) CMK Encryption for Azure Storage Accounts (3) CMK Encryption for Azure Storage Accounts (4) CMK Encryption for Azure Storage Accounts (5) CMK Encryption for Azure Storage Accounts (6)

Purpose of this post

The purpose of this post is to show you what kind of encryption Microsoft uses for encrypting storage accounts by default and how you can use CMK (Customer Managed Keys) to encrypt your storage accounts.

Encryption using Microsoft managed keys

By default, if you don't specify the type of encryption for your storage accounts while creation, Microsoft uses server-side encryption (SSE) to automatically encrypt your data. This is applied to any storage account regardless of its tier. Microsoft uses Microsoft managed keys for this type of encryption. This is the default option from Microsoft.

Encryption using Customer managed keys (CMK)

While you can continue to let Microsoft handle the encryption of your data, customers can use their own keys to handle data encryption. This type of encryption is called CMK enabled encryption. Here are some of the benefits of using CMK over default Microsoft managed keys.

  1. Customers have control over the keys used to encrypt their data.
  2. Microsoft rotates their keys as per their own compliance requirements. Customers using CMK can meet security compliance requirements.
  3. CMK keys are stored in customer's key vault, giving control over where these can be used.
  4. Same CMK keys can be used to encrypt multiple storage accounts.

Implementing CMK for storage accounts

In this section, we'll see how to implement CMK for storage accounts.

Examining default encryption for a storage account

Before implementing CMK, lets see how Microsoft encrypts storage account with Microsoft managed keys. While creating a storage account in the 'encryption' section, you can specify whether you would like go with default encryption or a customized encryption using CMK.

CMK Encryption for Azure Storage Accounts (7)

Once its created, you can see the type of encryption used by storage account as shown below:

CMK Encryption for Azure Storage Accounts (8)

If you would like to use CMK, you can do so, however the a new key has to be created and stored in Azure Key Vault and used for encryption. We'll see that in the next section.

Enabling CMK for a storage account

1.Create a new key in Azure key vault in the same region as storage account
2.Click on 'generate/import' under keys as shown below:

CMK Encryption for Azure Storage Accounts (9)

3.Give key a name and leave everything else to default as shown below.

CMK Encryption for Azure Storage Accounts (10)

4.Go back to storage account and encryption section.

CMK Encryption for Azure Storage Accounts (11)

CMK Encryption for Azure Storage Accounts (12)

After selecting the key it should show as following. Click 'save' to apply the settings

CMK Encryption for Azure Storage Accounts (13)

Once applied it would show that it is now using CMK for storage encryption.

CMK Encryption for Azure Storage Accounts (14)

As a part of this applying CMK encryption for storage accounts, it also creates a system assigned managed identity to the storage account and same is granted permission Azure Key Vault with 'get', 'wrap' and 'unwrap' permissions for the managed identity of storage account.

CMK Encryption for Azure Storage Accounts (15)

In this blog post, we have seen how to use customer managed keys for storage account encryption.

This brings us to the end of this blog post. Hope you enjoyed reading it.

Happy Learning!!!

Top comments (0)

Subscribe

For further actions, you may consider blocking this person and/or reporting abuse

CMK Encryption for Azure Storage Accounts (2024)
Top Articles
MDM Implementation: How to Implement Master Data Management
IRCTC.NS Intrinsic Value | Indian Railway Catering and Tourism Corporation Ltd (IRCTC.NS)
Somboun Asian Market
Urist Mcenforcer
Ffxiv Shelfeye Reaver
Craftsman M230 Lawn Mower Oil Change
Wisconsin Women's Volleyball Team Leaked Pictures
Top Financial Advisors in the U.S.
Erskine Plus Portal
Corpse Bride Soap2Day
Optum Medicare Support
Pbr Wisconsin Baseball
13 The Musical Common Sense Media
Gt Transfer Equivalency
454 Cu In Liters
Turning the System On or Off
7 Low-Carb Foods That Fill You Up - Keto Tips
Pricelinerewardsvisa Com Activate
Kamzz Llc
FDA Approves Arcutis’ ZORYVE® (roflumilast) Topical Foam, 0.3% for the Treatment of Seborrheic Dermatitis in Individuals Aged 9 Years and Older - Arcutis Biotherapeutics
Finalize Teams Yahoo Fantasy Football
Japanese Mushrooms: 10 Popular Varieties and Simple Recipes - Japan Travel Guide MATCHA
Zillow Group Stock Price | ZG Stock Quote, News, and History | Markets Insider
At&T Outage Today 2022 Map
Jordan Poyer Wiki
kvoa.com | News 4 Tucson
Cornedbeefapproved
Sinai Sdn 2023
How Do Netspend Cards Work?
Kelley Fliehler Wikipedia
Otis Offender Michigan
Stolen Touches Neva Altaj Read Online Free
Www Craigslist Com Shreveport Louisiana
How to Watch the X Trilogy Starring Mia Goth in Chronological Order
Arcadia Lesson Plan | Day 4: Crossword Puzzle | GradeSaver
Tds Wifi Outage
Elgin Il Building Department
Hindilinks4U Bollywood Action Movies
Temu Y2K
Craigslist Tulsa Ok Farm And Garden
Cranston Sewer Tax
Barstool Sports Gif
412Doctors
Timothy Warren Cobb Obituary
Professors Helpers Abbreviation
Dontrell Nelson - 2016 - Football - University of Memphis Athletics
Copd Active Learning Template
Bonecrusher Upgrade Rs3
The 13 best home gym equipment and machines of 2023
Kidcheck Login
Arnold Swansinger Family
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5687

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.