You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security/fundamentals/encryption-cmk-support.md
+66-14Lines changed: 66 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,9 +13,10 @@ ms.topic: article
13
13
14
14
The following services support server-side encryption with customer managed keys in [Azure Key Vault](/azure/key-vault/) and [Azure Managed HSM](/azure/key-vault/managed-hsm/). For implementation details, see the service-specific documentation or the service's [Microsofr Cloud Security Benchmark: security baseline](/security/benchmark/azure/security-baselines-overview) (section DP-5).
15
15
16
+
## AI and Machine Learning
17
+
16
18
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
|[Azure AI Search](/azure/search/)| Yes ||[Manage encryption keys in Azure Cognitive Search](/azure/search/search-security-manage-encryption-keys)|
20
21
|[Azure AI services](/azure/cognitive-services/)| Yes | Yes |[Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal)|
21
22
|[Azure AI Studio](/azure/ai-studio)| Yes ||[Encryption of data at rest in Azure AI services](/azure/ai-studio/concepts/encryption-keys-portal)|
@@ -33,7 +34,11 @@ The following services support server-side encryption with customer managed keys
33
34
|[QnA Maker](/azure/cognitive-services/qnamaker/)| Yes | Yes |[Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal)|
34
35
|[Speech Services](/azure/cognitive-services/speech-service/)| Yes | Yes |[Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal)|
35
36
|[Translator Text](/azure/cognitive-services/translator/)| Yes | Yes |[Use customer-managed keys for data encryption](/azure/cognitive-services/encryption/cognitive-services-encryption-keys-portal)|
36
-
|**Analytics**||||
37
+
38
+
## Analytics
39
+
40
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
41
+
|---|---|---|---|---|
37
42
|[Azure Data Explorer](/azure/data-explorer/)| Yes ||[Configure customer-managed keys (CMK) in Azure Data Explorer](/azure/data-explorer/customer-managed-keys-portal)|
38
43
|[Azure Data Factory](/azure/data-factory/)| Yes | Yes |[Encryption with customer-managed keys for Azure Data Factory](/azure/data-factory/enable-customer-managed-key)|
39
44
|[Azure Data Lake Store](/azure/data-lake-store/)| Yes (RSA 2048-bit) |||
@@ -46,12 +51,21 @@ The following services support server-side encryption with customer managed keys
46
51
|[Azure Synapse Analytics](/azure/synapse-analytics/)| Yes (RSA 3072-bit) | Yes |[Configure encryption at rest with customer-managed keys](/azure/synapse-analytics/security/workspaces-encryption)|
47
52
|[Microsoft Fabric](/fabric)| Yes ||[Customer-managed key (CMK) encryption and Microsoft Fabric](/fabric/security/security-scenario#customer-managed-key-cmk-encryption-and-microsoft-fabric)|
48
53
|[Power BI Embedded](/power-bi)| Yes ||[Using your own key for Power BI encryption (Preview)](/power-bi/enterprise/service-encryption-byok)|
49
-
|**Containers**||||
54
+
55
+
## Containers
56
+
57
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
58
+
|---|---|---|---|---|
50
59
|[Azure Kubernetes Service](/azure/aks/)| Yes | Yes |[Enable host encryption on your AKS cluster nodes](/azure/aks/enable-host-encryption)|
51
60
|[Azure Red Hat OpenShift](/azure/openshift/)| Yes ||[Bring your own keys (BYOK) with Azure Red Hat OpenShift](/azure/openshift/howto-byok)|
52
61
|[Container Instances](/azure/container-instances/)| Yes ||[Encrypt data with a customer-managed key](/azure/container-instances/container-instances-encrypt-data#encrypt-data-with-a-customer-managed-key)|
53
62
|[Container Registry](/azure/container-registry/)| Yes ||[Encrypt container images with a customer-managed key](/azure/container-registry/container-registry-customer-managed-keys)|
54
-
|**Compute**||||
63
+
64
+
65
+
## Compute
66
+
67
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
68
+
|---|---|---|---|---|
55
69
|[App Service](/azure/app-service/)| Yes\*\*| Yes |[Configure customer-managed keys for App Service](/azure/app-service/configure-encrypt-at-rest-using-cmk)|
56
70
|[Azure Functions](/azure/azure-functions/)| Yes\*\*| Yes |[Configure customer-managed keys for Azure Functions](/azure/azure-functions/configure-encrypt-at-rest-using-cmk)|
57
71
|[Azure HPC Cache](/azure/hpc-cache/)| Yes ||[Use customer-managed keys with HPC Cache](/azure/hpc-cache/customer-keys)|
@@ -63,7 +77,11 @@ The following services support server-side encryption with customer managed keys
63
77
|[Site Recovery](/azure/site-recovery/)| Yes ||[Enable replication with customer-managed keys](/azure/site-recovery/azure-to-azure-how-to-enable-replication-cmk-disks)|
64
78
|[Virtual Machine Scale Set](/azure/virtual-machine-scale-sets/)| Yes | Yes |[Encrypt virtual machine scale sets using the portal](/azure/virtual-machines/linux/disk-encryption-key-vault)|
65
79
|[Virtual Machines](/azure/virtual-machines/)| Yes | Yes |[Azure Disk Encryption for Windows and Linux VMs](/azure/virtual-machines/disk-encryption#customer-managed-keys)|
66
-
|**Databases**||||
80
+
81
+
## Databases
82
+
83
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
|[Azure Database for MySQL - Flexible Server](/azure/mysql/flexible-server/)| Yes ||[Data encryption with customer-managed keys in Azure Database for MySQL - Flexible Server](/azure/mysql/flexible-server/concepts-customer-managed-key)|
69
87
|[Azure Database for MySQL - Single Server](/azure/mysql/single-server/)| Yes ||[Azure Database for MySQL data encryption with a customer-managed key](/previous-versions/azure/mysql/single-server/concepts-data-encryption-mysql)|
@@ -77,30 +95,58 @@ The following services support server-side encryption with customer managed keys
77
95
|[SQL Server on Virtual Machines](/azure/virtual-machines/windows/sql/)| Yes ||[Transparent data encryption for SQL Server on Azure VM](/azure/virtual-machines/windows/sql/virtual-machines-windows-sql-security#transparent-data-encryption)|
78
96
|[SQL Server Stretch Database](/azure/sql-server-stretch-database/)| Yes (RSA 3072-bit) |||
79
97
|[Table Storage](/azure/storage/tables/)| Yes ||[Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview)|
80
-
|**Hybrid + Multicloud**||||
98
+
99
+
## Hybrid + Multicloud
100
+
101
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
102
+
|---|---|---|---|---|
81
103
|[Azure Stack Edge](/azure/databox-online/)| Yes ||[Protect data at rest on Azure Stack Edge Pro R](/azure/databox-online/azure-stack-edge-pro-r-security#protect-data-at-rest)|
82
-
|**Integration**||||
104
+
105
+
## Integration
106
+
107
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
108
+
|---|---|---|---|---|
83
109
|[Azure Health Data Services](/azure/healthcare-apis/)| Yes ||[Configure customer-managed keys for Azure Health Data Services DICOM](/azure/healthcare-apis/dicom/configure-customer-managed-keys), [Configure customer-managed keys for Azure Health Data Services FHIR](/azure/healthcare-apis/fhir/configure-customer-managed-keys)|
84
110
|[Event Hubs](/azure/event-hubs/)| Yes ||[Configure customer-managed keys for encryption](/azure/event-hubs/configure-customer-managed-key)|
85
111
|[Logic Apps](/azure/logic-apps/)| Yes |||
86
112
|[Service Bus](/azure/service-bus-messaging/)| Yes ||[Configure customer-managed keys for encryption](/azure/service-bus-messaging/configure-customer-managed-key)|
87
-
|**IoT Services**||||
113
+
114
+
## IoT Services
115
+
116
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
117
+
|---|---|---|---|---|
88
118
|[Device Update for IoT Hub](/azure/iot-hub-device-update/)| Yes | Yes |[Data encryption for Device Update for IoT Hub](/azure/iot-hub-device-update/device-update-data-encryption)|
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
124
+
|---|---|---|---|---|
91
125
|[App Configuration](/azure/azure-app-configuration/)| Yes ||[Use customer-managed keys to encrypt data](/azure/azure-app-configuration/concept-customer-managed-keys)|
92
126
|[Automation](/azure/automation/)| Yes ||[Encryption of automation assets](/azure/automation/automation-secure-asset-encryption)|
93
127
|[Azure Migrate](/azure/migrate/)| Yes ||[Tutorial: Migrate VMware VMs to Azure](/azure/migrate/tutorial-migrate-vmware)|
94
128
|[Azure Monitor](/azure/azure-monitor)| Yes ||[Customer-managed keys in Azure Monitor](/azure/azure-monitor/logs/customer-managed-keys)|
95
-
|**Media**||||
129
+
130
+
## Media
131
+
132
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
133
+
|---|---|---|---|---|
96
134
|[Azure Communication Services](/azure/communication-services/)| Yes ||[Data encryption in Azure Communication Services](/azure/communications-gateway/security#data-retention-data-security-and-encryption-at-rest)|
97
135
|[Media Services](/azure/media-services/)| Yes ||[Use your own encryption keys with Azure Media Services](/azure/media-services/latest/concept-use-customer-managed-keys-byok)|
98
-
|**Security**||||
136
+
137
+
## Security
138
+
139
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
140
+
|---|---|---|---|---|
99
141
|[Azure Information Protection](/azure/information-protection/)| Yes ||[How are the Azure Rights Management cryptographic keys managed and secured?](/azure/information-protection/how-does-it-work#how-the-azure-rms-cryptographic-keys-are-stored-and-secured)|
100
142
|[Microsoft Defender for Cloud](/azure/defender-for-cloud/)| Yes ||[Customer-managed keys in Azure Monitor](/azure/azure-monitor/logs/customer-managed-keys)|
101
143
|[Microsoft Defender for IoT](/azure/defender-for-iot/)| Yes |||
102
144
|[Microsoft Sentinel](/azure/sentinel/)| Yes | Yes |[Encryption at rest in Microsoft Sentinel](/azure/sentinel/customer-managed-keys)|
103
-
|**Storage**||||
145
+
146
+
## Storage
147
+
148
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
149
+
|---|---|---|---|---|
104
150
|[Archive Storage](/azure/storage/blobs/archive-blob)| Yes ||[Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview)|
105
151
|[Azure Backup](/azure/backup/)| Yes | Yes |[Encrypt backup data using customer-managed keys](/azure/backup/encryption-at-rest-with-cmk)|
106
152
|[Azure Cache for Redis](/azure/azure-cache-for-redis/)| Yes\*\*\*| Yes |[Configure disk encryption for Azure Cache for Redis instances using customer managed keys](/azure/azure-cache-for-redis/cache-how-to-encryption)|
@@ -117,9 +163,15 @@ The following services support server-side encryption with customer managed keys
|[Ultra Disk Storage](/azure/virtual-machines/disks-types/)| Yes | Yes |[Azure Disk Encryption for Windows and Linux VMs](/azure/virtual-machines/disk-encryption#customer-managed-keys)|
120
-
|**Other**||||
166
+
167
+
## Other
168
+
169
+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
170
+
|---|---|---|---|---|
121
171
|[Universal Print](/universal-print/)| Yes ||[Data encryption in Universal Print](/universal-print/fundamentals/universal-print-encryption)|
122
172
173
+
## Caveats
174
+
123
175
\* This service doesn't persist data. Transient caches, if any, are encrypted with a Microsoft key.
124
176
125
177
\*\* This service supports storing data in your own Key Vault, Storage Account, or other data persisting service that already supports Server-Side Encryption with Customer-Managed Key.
0 commit comments