-All secrets in your Key Vault are stored encrypted. Key Vault encrypts secrets at rest with a hierarchy of encryption keys, with all keys in that hierarchy are protected by modules that are FIPS 140-2 compliant. In all regions other than China, the root of that key hierarchy is protected by a module that is validated for FIPS 140-2 Level 2 or higher. In China, the root of that hierarchy is protected by a module that is validated for FIPS 140-2 Level 1. This encryption is transparent, and requires no action from the user. The Azure Key Vault service encrypts your secrets when you add them, and decrypts them automatically when you read them. The encryption key is unique to each key vault.
0 commit comments