Skip to content

Commit 18f8c8b

Browse files
committed
update
1 parent ce3ccff commit 18f8c8b

File tree

2 files changed

+74
-22
lines changed

2 files changed

+74
-22
lines changed

articles/security/fundamentals/encryption-cmk-support.md

Lines changed: 66 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,10 @@ ms.topic: article
1313

1414
The following services support server-side encryption with customer managed keys in [Azure Key Vault](/azure/key-vault/) and [Azure Managed HSM](/azure/key-vault/managed-hsm/). For implementation details, see the service-specific documentation or the service's [Microsofr Cloud Security Benchmark: security baseline](/security/benchmark/azure/security-baselines-overview) (section DP-5).
1515

16+
## AI and Machine Learning
17+
1618
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
17-
|----------------------------------------------------------------------|-----------|-------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------|
18-
| **AI and Machine Learning** | | | |
19+
|---|---|---|---|---|
1920
| [Azure AI Search](/azure/search/) | Yes | | [Manage encryption keys in Azure Cognitive Search](/azure/search/search-security-manage-encryption-keys) |
2021
| [Azure AI services](/azure/cognitive-services/) | Yes | Yes | [Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal) |
2122
| [Azure AI Studio](/azure/ai-studio) | Yes | | [Encryption of data at rest in Azure AI services](/azure/ai-studio/concepts/encryption-keys-portal) |
@@ -33,7 +34,11 @@ The following services support server-side encryption with customer managed keys
3334
| [QnA Maker](/azure/cognitive-services/qnamaker/) | Yes | Yes | [Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal) |
3435
| [Speech Services](/azure/cognitive-services/speech-service/) | Yes | Yes | [Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal) |
3536
| [Translator Text](/azure/cognitive-services/translator/) | Yes | Yes | [Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal) |
36-
| **Analytics** | | | |
37+
38+
## Analytics
39+
40+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
41+
|---|---|---|---|---|
3742
| [Azure Data Explorer](/azure/data-explorer/) | Yes | | [Configure customer-managed keys (CMK) in Azure Data Explorer](/azure/data-explorer/customer-managed-keys-portal) |
3843
| [Azure Data Factory](/azure/data-factory/) | Yes | Yes | [Encryption with customer-managed keys for Azure Data Factory](/azure/data-factory/enable-customer-managed-key) |
3944
| [Azure Data Lake Store](/azure/data-lake-store/) | Yes (RSA 2048-bit) | | |
@@ -46,12 +51,21 @@ The following services support server-side encryption with customer managed keys
4651
| [Azure Synapse Analytics](/azure/synapse-analytics/) | Yes (RSA 3072-bit) | Yes | [Configure encryption at rest with customer-managed keys](/azure/synapse-analytics/security/workspaces-encryption) |
4752
| [Microsoft Fabric](/fabric) | Yes | | [Customer-managed key (CMK) encryption and Microsoft Fabric](/fabric/security/security-scenario#customer-managed-key-cmk-encryption-and-microsoft-fabric) |
4853
| [Power BI Embedded](/power-bi) | Yes | | [Using your own key for Power BI encryption (Preview)](/power-bi/enterprise/service-encryption-byok) |
49-
| **Containers** | | | |
54+
55+
## Containers
56+
57+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
58+
|---|---|---|---|---|
5059
| [Azure Kubernetes Service](/azure/aks/) | Yes | Yes | [Enable host encryption on your AKS cluster nodes](/azure/aks/enable-host-encryption) |
5160
| [Azure Red Hat OpenShift](/azure/openshift/) | Yes | | [Bring your own keys (BYOK) with Azure Red Hat OpenShift](/azure/openshift/howto-byok) |
5261
| [Container Instances](/azure/container-instances/) | Yes | | [Encrypt data with a customer-managed key](/azure/container-instances/container-instances-encrypt-data#encrypt-data-with-a-customer-managed-key) |
5362
| [Container Registry](/azure/container-registry/) | Yes | | [Encrypt container images with a customer-managed key](/azure/container-registry/container-registry-customer-managed-keys) |
54-
| **Compute** | | | |
63+
64+
65+
## Compute
66+
67+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
68+
|---|---|---|---|---|
5569
| [App Service](/azure/app-service/) | Yes\*\* | Yes | [Configure customer-managed keys for App Service](/azure/app-service/configure-encrypt-at-rest-using-cmk) |
5670
| [Azure Functions](/azure/azure-functions/) | Yes\*\* | Yes | [Configure customer-managed keys for Azure Functions](/azure/azure-functions/configure-encrypt-at-rest-using-cmk) |
5771
| [Azure HPC Cache](/azure/hpc-cache/) | Yes | | [Use customer-managed keys with HPC Cache](/azure/hpc-cache/customer-keys) |
@@ -63,7 +77,11 @@ The following services support server-side encryption with customer managed keys
6377
| [Site Recovery](/azure/site-recovery/) | Yes | | [Enable replication with customer-managed keys](/azure/site-recovery/azure-to-azure-how-to-enable-replication-cmk-disks) |
6478
| [Virtual Machine Scale Set](/azure/virtual-machine-scale-sets/) | Yes | Yes | [Encrypt virtual machine scale sets using the portal](/azure/virtual-machines/linux/disk-encryption-key-vault) |
6579
| [Virtual Machines](/azure/virtual-machines/) | Yes | Yes | [Azure Disk Encryption for Windows and Linux VMs](/azure/virtual-machines/disk-encryption#customer-managed-keys) |
66-
| **Databases** | | | |
80+
81+
## Databases
82+
83+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
84+
|---|---|---|---|---|
6785
| [Azure Cosmos DB](/azure/cosmos-db/) | Yes | Yes | [Configure customer-managed keys using Azure Key Vault](/azure/cosmos-db/how-to-setup-cmk), [Configure customer-managed keys using Azure Key Vault Managed HSM](/azure/cosmos-db/how-to-setup-customer-managed-keys-mhsm) |
6886
| [Azure Database for MySQL - Flexible Server](/azure/mysql/flexible-server/) | Yes | | [Data encryption with customer-managed keys in Azure Database for MySQL - Flexible Server](/azure/mysql/flexible-server/concepts-customer-managed-key) |
6987
| [Azure Database for MySQL - Single Server](/azure/mysql/single-server/) | Yes | | [Azure Database for MySQL data encryption with a customer-managed key](/previous-versions/azure/mysql/single-server/concepts-data-encryption-mysql) |
@@ -77,30 +95,58 @@ The following services support server-side encryption with customer managed keys
7795
| [SQL Server on Virtual Machines](/azure/virtual-machines/windows/sql/) | Yes | | [Transparent data encryption for SQL Server on Azure VM](/azure/virtual-machines/windows/sql/virtual-machines-windows-sql-security#transparent-data-encryption) |
7896
| [SQL Server Stretch Database](/azure/sql-server-stretch-database/) | Yes (RSA 3072-bit) | | |
7997
| [Table Storage](/azure/storage/tables/) | Yes | | [Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview) |
80-
| **Hybrid + Multicloud** | | | |
98+
99+
## Hybrid + Multicloud
100+
101+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
102+
|---|---|---|---|---|
81103
| [Azure Stack Edge](/azure/databox-online/) | Yes | | [Protect data at rest on Azure Stack Edge Pro R](/azure/databox-online/azure-stack-edge-pro-r-security#protect-data-at-rest) |
82-
| **Integration** | | | |
104+
105+
## Integration
106+
107+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
108+
|---|---|---|---|---|
83109
| [Azure Health Data Services](/azure/healthcare-apis/) | Yes | | [Configure customer-managed keys for Azure Health Data Services DICOM](/azure/healthcare-apis/dicom/configure-customer-managed-keys), [Configure customer-managed keys for Azure Health Data Services FHIR](/azure/healthcare-apis/fhir/configure-customer-managed-keys) |
84110
| [Event Hubs](/azure/event-hubs/) | Yes | | [Configure customer-managed keys for encryption](/azure/event-hubs/configure-customer-managed-key) |
85111
| [Logic Apps](/azure/logic-apps/) | Yes | | |
86112
| [Service Bus](/azure/service-bus-messaging/) | Yes | | [Configure customer-managed keys for encryption](/azure/service-bus-messaging/configure-customer-managed-key) |
87-
| **IoT Services** | | | |
113+
114+
## IoT Services
115+
116+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
117+
|---|---|---|---|---|
88118
| [Device Update for IoT Hub](/azure/iot-hub-device-update/) | Yes | Yes | [Data encryption for Device Update for IoT Hub](/azure/iot-hub-device-update/device-update-data-encryption) |
89119
| [IoT Hub Device Provisioning](/azure/iot-dps/) | Yes | | |
90-
| **Management and Governance** | | | |
120+
121+
## Management and Governance
122+
123+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
124+
|---|---|---|---|---|
91125
| [App Configuration](/azure/azure-app-configuration/) | Yes | | [Use customer-managed keys to encrypt data](/azure/azure-app-configuration/concept-customer-managed-keys) |
92126
| [Automation](/azure/automation/) | Yes | | [Encryption of automation assets](/azure/automation/automation-secure-asset-encryption) |
93127
| [Azure Migrate](/azure/migrate/) | Yes | | [Tutorial: Migrate VMware VMs to Azure](/azure/migrate/tutorial-migrate-vmware) |
94128
| [Azure Monitor](/azure/azure-monitor) | Yes | | [Customer-managed keys in Azure Monitor](/azure/azure-monitor/logs/customer-managed-keys) |
95-
| **Media** | | | |
129+
130+
## Media
131+
132+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
133+
|---|---|---|---|---|
96134
| [Azure Communication Services](/azure/communication-services/) | Yes | | [Data encryption in Azure Communication Services](/azure/communications-gateway/security#data-retention-data-security-and-encryption-at-rest) |
97135
| [Media Services](/azure/media-services/) | Yes | | [Use your own encryption keys with Azure Media Services](/azure/media-services/latest/concept-use-customer-managed-keys-byok) |
98-
| **Security** | | | |
136+
137+
## Security
138+
139+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
140+
|---|---|---|---|---|
99141
| [Azure Information Protection](/azure/information-protection/) | Yes | | [How are the Azure Rights Management cryptographic keys managed and secured?](/azure/information-protection/how-does-it-work#how-the-azure-rms-cryptographic-keys-are-stored-and-secured) |
100142
| [Microsoft Defender for Cloud](/azure/defender-for-cloud/) | Yes | | [Customer-managed keys in Azure Monitor](/azure/azure-monitor/logs/customer-managed-keys) |
101143
| [Microsoft Defender for IoT](/azure/defender-for-iot/) | Yes | | |
102144
| [Microsoft Sentinel](/azure/sentinel/) | Yes | Yes | [Encryption at rest in Microsoft Sentinel](/azure/sentinel/customer-managed-keys) |
103-
| **Storage** | | | |
145+
146+
## Storage
147+
148+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
149+
|---|---|---|---|---|
104150
| [Archive Storage](/azure/storage/blobs/archive-blob) | Yes | | [Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview) |
105151
| [Azure Backup](/azure/backup/) | Yes | Yes | [Encrypt backup data using customer-managed keys](/azure/backup/encryption-at-rest-with-cmk) |
106152
| [Azure Cache for Redis](/azure/azure-cache-for-redis/) | Yes\*\*\* | Yes | [Configure disk encryption for Azure Cache for Redis instances using customer managed keys](/azure/azure-cache-for-redis/cache-how-to-encryption) |
@@ -117,9 +163,15 @@ The following services support server-side encryption with customer managed keys
117163
| [Queue Storage](/azure/storage/queues/) | Yes | Yes | [Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview) |
118164
| [StorSimple](/azure/storsimple/) | Yes | | [Azure StorSimple security features](/azure/storsimple/storsimple-security#data-encryption) |
119165
| [Ultra Disk Storage](/azure/virtual-machines/disks-types/) | Yes | Yes | [Azure Disk Encryption for Windows and Linux VMs](/azure/virtual-machines/disk-encryption#customer-managed-keys) |
120-
| **Other** | | | |
166+
167+
## Other
168+
169+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
170+
|---|---|---|---|---|
121171
| [Universal Print](/universal-print/) | Yes | | [Data encryption in Universal Print](/universal-print/fundamentals/universal-print-encryption) |
122172

173+
## Caveats
174+
123175
\* This service doesn't persist data. Transient caches, if any, are encrypted with a Microsoft key.
124176

125177
\*\* This service supports storing data in your own Key Vault, Storage Account, or other data persisting service that already supports Server-Side Encryption with Customer-Managed Key.

0 commit comments

Comments
 (0)