Overview of Key Management in Azure (2024)

  • Article

Note

Zero Trust is a security strategy comprising three principles: "Verify explicitly", "Use least privilege access", and "Assume breach". Data protection, including key management, supports the "use least privilege access" principle. For more information, see What is Zero Trust?

In Azure, encryption keys can be either platform managed or customer managed.

Platform-managed keys (PMKs) are encryption keys generated, stored, and managed entirely by Azure. Customers do not interact with PMKs. The keys used for Azure Data Encryption-at-Rest, for instance, are PMKs by default.

Customer-managed keys (CMK), on the other hand, are keys read, created, deleted, updated, and/or administered by one or more customers. Keys stored in a customer-owned key vault or hardware security module (HSM) are CMKs. Bring Your Own Key (BYOK) is a CMK scenario in which a customer imports (brings) keys from an outside storage location into an Azure key management service (see the Azure Key Vault: Bring your own key specification).

A specific type of customer-managed key is the "key encryption key" (KEK). A KEK is a primary key that controls access to one or more encryption keys that are themselves encrypted.

Customer-managed keys can be stored on-premises or, more commonly, in a cloud key management service.

Azure key management services

Azure offers several options for storing and managing your keys in the cloud, including Azure Key Vault, Azure Managed HSM, Azure Dedicated HSM, and Azure Payment HSM. These options differ in terms of their FIPS compliance level, management overhead, and intended applications.

For an overview of each key management service and a comprehensive guide to choosing the right key management solution for you, see How to Choose the Right Key Management Solution.

Pricing

The Azure Key Vault Standard and Premium tiers are billed on a transactional basis, with an additional monthly per-key charge for premium hardware-backed keys. Managed HSM, Dedicated HSM, and Payments HSM don't charge on a transactional basis; instead they are always-in-use devices that are billed at a fixed hourly rate. For detailed pricing information, see Key Vault pricing, Dedicated HSM pricing, and Payment HSM pricing.

Service Limits

Managed HSM, Dedicated HSM, and Payments HSM offer dedicated capacity. Key Vault Standard and Premium are multi-tenant offerings and have throttling limits. For service limits, see Key Vault service limits.

Encryption-At-Rest

Azure Key Vault and Azure Key Vault Managed HSM have integrations with Azure Services and Microsoft 365 for Customer Managed Keys, meaning customers may use their own keys in Azure Key Vault and Azure Key Managed HSM for encryption-at-rest of data stored in these services. Dedicated HSM and Payments HSM are Infrastructure-as-Service offerings and do not offer integrations with Azure Services. For an overview of encryption-at-rest with Azure Key Vault and Managed HSM, see Azure Data Encryption-at-Rest.

APIs

Dedicated HSM and Payments HSM support the PKCS#11, JCE/JCA, and KSP/CNG APIs, but Azure Key Vault and Managed HSM do not. Azure Key Vault and Managed HSM use the Azure Key Vault REST API and offer SDK support. For more information on the Azure Key Vault API, see Azure Key Vault REST API Reference.

What's next

Overview of Key Management in Azure (2024)

FAQs

What is Azure managed keys? ›

The keys used for Azure Data Encryption-at-Rest, for instance, are PMKs by default. Customer-managed keys (CMK), on the other hand, are keys read, created, deleted, updated, and/or administered by one or more customers. Keys stored in a customer-owned key vault or hardware security module (HSM) are CMKs.

Which of the following is a key management system in Azure? ›

Azure Key Vault is one of several key management solutions in Azure, and helps solve the following problems: Secrets Management - Azure Key Vault can be used to Securely store and tightly control access to tokens, passwords, certificates, API keys, and other secrets.

What are key services of Azure? ›

  • Azure Virtual Machines.
  • Azure Virtual Desktop.
  • Azure SQL.
  • Microsoft Copilot in Azure PREVIEW.
  • Azure AI Services.
  • Azure AI Studio.
  • Azure Cosmos DB.
  • Azure Kubernetes Service (AKS)

What are keys used for in Azure? ›

Azure Key Vault is a cloud service for securely storing and accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, certificates, or cryptographic keys. Key Vault service supports two types of containers: vaults and managed hardware security module(HSM) pools.

How are keys managed? ›

Key Management is the process of putting certain standards in place to ensure the security of cryptographic keys in an organization. Key Management deal with the creation, exchange, storage, deletion, and refreshing of keys. They also deal with the members access of the keys.

How do I manage access keys in Azure? ›

In the Azure portal, go to your storage account. Under Security + networking, select Access keys. Your account access keys appear, as well as the complete connection string for each key. Select Show keys to show your access keys and connection strings and to enable buttons to copy the values.

What is the description of key management system? ›

Definitions: A system for the management of cryptographic keys and their metadata (e.g., generation, distribution, storage, backup, archive, recovery, use, revocation, and destruction). An automated key management system may be used to oversee, automate, and secure the key management process.

What is the function of key management system? ›

The purpose of the key management is the key of the production, storage, distribution, update, control and destroyed in the process of the whole life cycle to ensure the safety of the key.

What is considered key management? ›

Key management refers to the process of handling cryptographic keys throughout their lifecycle. This includes their creation, distribution, storage, rotation, and deletion.

What are the three services in Azure? ›

The three categories of service that Microsoft Azure can provide for businesses are:
  • Infrastructure as a Service (IaaS)
  • Platform as a Service (PaaS)
  • Software as a Service (SaaS)
Apr 6, 2023

What is the overview of Azure? ›

Azure is a cloud platform with more than 200 products and services designed to help you bring new solutions to life—to solve today's challenges and create the future. Use the tools and frameworks of your choice to build, run, and manage applications across cloud, hybrid, and edge environments.

What key types are available in Azure key vault? ›

Azure Key Vault provides two types of resources to store and manage cryptographic keys. Vaults support software-protected and HSM-protected (Hardware Security Module) keys. Managed HSMs only support HSM-protected keys.

What is the key feature of Azure? ›

Microsoft Azure provides a wide range of features and benefits for businesses of all sizes, and it is a powerful cloud computing platform that provides businesses with a range of benefits, including scalability, flexibility, security, cost savings, disaster recovery, collaboration, and advanced analytics.

What are Azure function keys? ›

Azure Functions provide a way to secure HTTP function endpoints during development using function access keys. These keys are required in the request unless the HTTP access level is set to anonymous.

Why use customer-managed keys in Azure? ›

You can use your own encryption key to protect the data in your storage account. When you specify a customer-managed key, that key is used to protect and control access to the key that encrypts your data. Customer-managed keys offer greater flexibility to manage access controls.

Which Microsoft Azure offering can be used for key management? ›

Azure offers multiple solutions for cryptographic key storage and management in the cloud: Azure Key Vault (standard and premium offerings), Azure Managed HSM, Azure Dedicated HSM, and Azure Payment HSM.

What is Microsoft Key Management Service? ›

KMS (Key Management Service) is one of the methods to activate Microsoft Windows and Microsoft Office. Activation ensures that the software is obtained from and licensed by Microsoft. KMS is used by volume license customers, usually medium to large businesses, schools, and non-profits.

What is keyvault in Azure? ›

Azure Key Vault is a cloud service that provides a secure store for secrets. You can securely store keys, passwords, certificates, and other secrets. Azure key vaults may be created and managed through the Azure portal. In this quickstart, you create a key vault, then use it to store a secret.

What is the main management tool used for managing Azure resources? ›

Azure Portal is a web-based graphical interface for managing Azure services. It provides a unified, scalable, and secure way to manage resources and services in Azure, including virtual machines, storage accounts, databases, and other Azure services.

Top Articles
Can I get a loan with no credit score in South Africa? - RCS Group
5-4-1 system in football: characteristics and summary
Diario Las Americas Rentas Hialeah
Breaded Mushrooms
Myexperience Login Northwell
From Algeria to Uzbekistan-These Are the Top Baby Names Around the World
B67 Bus Time
Strange World Showtimes Near Cmx Downtown At The Gardens 16
Moe Gangat Age
Audrey Boustani Age
Shuiby aslam - ForeverMissed.com Online Memorials
‘Accused: Guilty Or Innocent?’: A&E Delivering Up-Close Look At Lives Of Those Accused Of Brutal Crimes
My.doculivery.com/Crowncork
Calmspirits Clapper
Five Day National Weather Forecast
800-695-2780
DBZ Dokkan Battle Full-Power Tier List [All Cards Ranked]
My Homework Lesson 11 Volume Of Composite Figures Answer Key
Vegas7Games.com
Boscov's Bus Trips
Www.dunkinbaskinrunsonyou.con
Bidrl.com Visalia
Bfsfcu Truecar
Riverstock Apartments Photos
Log in or sign up to view
Elanco Rebates.com 2022
Wega Kit Filtros Fiat Cronos Argo 1.8 E-torq + Aceite 5w30 5l
3 Bedroom 1 Bath House For Sale
Moses Lake Rv Show
Wildfangs Springfield
2008 Chevrolet Corvette for sale - Houston, TX - craigslist
ATM Near Me | Find The Nearest ATM Location | ATM Locator NL
Anguilla Forum Tripadvisor
Tsbarbiespanishxxl
11526 Lake Ave Cleveland Oh 44102
Wunderground Orlando
Who Is Responsible for Writing Obituaries After Death? | Pottstown Funeral Home & Crematory
Trivago Sf
Sour OG is a chill recreational strain -- just have healthy snacks nearby (cannabis review)
Blow Dry Bar Boynton Beach
Cult Collectibles - True Crime, Cults, and Murderabilia
Kate Spade Outlet Altoona
Craigslist Chautauqua Ny
Blippi Park Carlsbad
Great Clips Virginia Center Commons
Craigslist Cars For Sale By Owner Memphis Tn
Razor Edge Gotti Pitbull Price
Craigslist Psl
David Turner Evangelist Net Worth
Dumb Money Showtimes Near Regal Stonecrest At Piper Glen
Law Students
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 6701

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.