CMK Encryption for Azure Storage Accounts (2024)

CMK Encryption for Azure Storage Accounts (1)

Vivekanand Rapaka

Posted on

CMK Encryption for Azure Storage Accounts (2) CMK Encryption for Azure Storage Accounts (3) CMK Encryption for Azure Storage Accounts (4) CMK Encryption for Azure Storage Accounts (5) CMK Encryption for Azure Storage Accounts (6)

Purpose of this post

The purpose of this post is to show you what kind of encryption Microsoft uses for encrypting storage accounts by default and how you can use CMK (Customer Managed Keys) to encrypt your storage accounts.

Encryption using Microsoft managed keys

By default, if you don't specify the type of encryption for your storage accounts while creation, Microsoft uses server-side encryption (SSE) to automatically encrypt your data. This is applied to any storage account regardless of its tier. Microsoft uses Microsoft managed keys for this type of encryption. This is the default option from Microsoft.

Encryption using Customer managed keys (CMK)

While you can continue to let Microsoft handle the encryption of your data, customers can use their own keys to handle data encryption. This type of encryption is called CMK enabled encryption. Here are some of the benefits of using CMK over default Microsoft managed keys.

  1. Customers have control over the keys used to encrypt their data.
  2. Microsoft rotates their keys as per their own compliance requirements. Customers using CMK can meet security compliance requirements.
  3. CMK keys are stored in customer's key vault, giving control over where these can be used.
  4. Same CMK keys can be used to encrypt multiple storage accounts.

Implementing CMK for storage accounts

In this section, we'll see how to implement CMK for storage accounts.

Examining default encryption for a storage account

Before implementing CMK, lets see how Microsoft encrypts storage account with Microsoft managed keys. While creating a storage account in the 'encryption' section, you can specify whether you would like go with default encryption or a customized encryption using CMK.

CMK Encryption for Azure Storage Accounts (7)

Once its created, you can see the type of encryption used by storage account as shown below:

CMK Encryption for Azure Storage Accounts (8)

If you would like to use CMK, you can do so, however the a new key has to be created and stored in Azure Key Vault and used for encryption. We'll see that in the next section.

Enabling CMK for a storage account

1.Create a new key in Azure key vault in the same region as storage account
2.Click on 'generate/import' under keys as shown below:

CMK Encryption for Azure Storage Accounts (9)

3.Give key a name and leave everything else to default as shown below.

CMK Encryption for Azure Storage Accounts (10)

4.Go back to storage account and encryption section.

CMK Encryption for Azure Storage Accounts (11)

CMK Encryption for Azure Storage Accounts (12)

After selecting the key it should show as following. Click 'save' to apply the settings

CMK Encryption for Azure Storage Accounts (13)

Once applied it would show that it is now using CMK for storage encryption.

CMK Encryption for Azure Storage Accounts (14)

As a part of this applying CMK encryption for storage accounts, it also creates a system assigned managed identity to the storage account and same is granted permission Azure Key Vault with 'get', 'wrap' and 'unwrap' permissions for the managed identity of storage account.

CMK Encryption for Azure Storage Accounts (15)

In this blog post, we have seen how to use customer managed keys for storage account encryption.

This brings us to the end of this blog post. Hope you enjoyed reading it.

Happy Learning!!!

Top comments (0)

Subscribe

For further actions, you may consider blocking this person and/or reporting abuse

CMK Encryption for Azure Storage Accounts (2024)
Top Articles
Passive Loss: Meaning, Overview, Types in Investing
Pokémon: The Real Reason Ash's Pikachu Is So Overpowered
Walgreens Boots Alliance, Inc. (WBA) Stock Price, News, Quote & History - Yahoo Finance
Sprinter Tyrone's Unblocked Games
Metallica - Blackened Lyrics Meaning
4-Hour Private ATV Riding Experience in Adirondacks 2024 on Cool Destinations
Unity Stuck Reload Script Assemblies
Booknet.com Contract Marriage 2
Ofw Pinoy Channel Su
Fusion
No Credit Check Apartments In West Palm Beach Fl
New Mexico Craigslist Cars And Trucks - By Owner
Beau John Maloney Houston Tx
Red Tomatoes Farmers Market Menu
Used Drum Kits Ebay
DoorDash, Inc. (DASH) Stock Price, Quote & News - Stock Analysis
Nutrislice Menus
Vermont Craigs List
Walgreens Alma School And Dynamite
Atdhe Net
Happy Life 365, Kelly Weekers | 9789021569444 | Boeken | bol
Yog-Sothoth
At&T Outage Today 2022 Map
Dark Entreaty Ffxiv
eugene bicycles - craigslist
2021 MTV Video Music Awards: See the Complete List of Nominees - E! Online
Is Poke Healthy? Benefits, Risks, and Tips
Chelsea Hardie Leaked
UAE 2023 F&B Data Insights: Restaurant Population and Traffic Data
LG UN90 65" 4K Smart UHD TV - 65UN9000AUJ | LG CA
Ehome America Coupon Code
A Plus Nails Stewartville Mn
Gyeon Jahee
Craigslist Albany Ny Garage Sales
Indiana Wesleyan Transcripts
Mistress Elizabeth Nyc
Chatropolis Call Me
Timberwolves Point Guard History
2007 Peterbilt 387 Fuse Box Diagram
Mugshots Journal Star
Clausen's Car Wash
Windshield Repair & Auto Glass Replacement in Texas| Safelite
Sallisaw Bin Store
Craigslist Minneapolis Com
2013 Honda Odyssey Serpentine Belt Diagram
Tom Kha Gai Soup Near Me
Holzer Athena Portal
John Wick: Kapitel 4 (2023)
Zeeks Pizza Calories
The Missile Is Eepy Origin
Bumgarner Funeral Home Troy Nc Obituaries
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5687

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.