Skip to content

Commit 66569fc

Browse files
committed
update
1 parent 0da35e9 commit 66569fc

File tree

1 file changed

+94
-103
lines changed

1 file changed

+94
-103
lines changed

articles/security/fundamentals/encryption-models.md

Lines changed: 94 additions & 103 deletions
Original file line numberDiff line numberDiff line change
@@ -128,109 +128,100 @@ When server-side encryption using customer-managed keys in customer-controlled h
128128
- Significant setup, configuration, and ongoing maintenance costs
129129
- Increased dependency on network availability between the customer datacenter and Azure datacenters.
130130

131-
## Supporting services
132-
133-
The Azure services that support each encryption model:
134-
135-
| Product, Feature, or Service | Server-Side Using Customer-Managed Key | Documentation |
136-
| --- | --- | --- |
137-
| **AI and Machine Learning** | | |
138-
| [Azure AI Search](/azure/search/) | Yes | |
139-
| [Azure AI services](/azure/cognitive-services/) | Yes, including Managed HSM | |
140-
| [Azure Machine Learning](/azure/machine-learning/) | Yes | |
141-
| [Content Moderator](/azure/cognitive-services/content-moderator/) | Yes, including Managed HSM | |
142-
| [Face](/azure/cognitive-services/face/) | Yes, including Managed HSM | |
143-
| [Language Understanding](/azure/cognitive-services/luis/) | Yes, including Managed HSM | |
144-
| [Azure OpenAI](/azure/ai-services/openai/) | Yes, including Managed HSM | |
145-
| [Personalizer](/azure/cognitive-services/personalizer/) | Yes, including Managed HSM | |
146-
| [QnA Maker](/azure/cognitive-services/qnamaker/) | Yes, including Managed HSM | |
147-
| [Speech Services](/azure/cognitive-services/speech-service/) | Yes, including Managed HSM | |
148-
| [Translator Text](/azure/cognitive-services/translator/) | Yes, including Managed HSM | |
149-
| [Power Platform](/power-platform/) | Yes, including Managed HSM | |
150-
| [Dataverse](/powerapps/maker/data-platform/) | Yes, including Managed HSM | |
151-
| [Dynamics 365](/dynamics365/) | Yes, including Managed HSM | |
152-
| **Analytics** | | |
153-
| [Azure Stream Analytics](/azure/stream-analytics/) | Yes\*\*, including Managed HSM | |
154-
| [Event Hubs](/azure/event-hubs/) | Yes | |
155-
| [Functions](/azure/azure-functions/) | Yes | |
156-
| [Azure Analysis Services](/azure/analysis-services/) | - | |
157-
| [Azure Data Catalog](/azure/data-catalog/) | - | |
158-
| [Azure HDInsight](/azure/hdinsight/) | Yes | |
159-
| [Azure Monitor Application Insights](/azure/azure-monitor/app/app-insights-overview) | Yes | |
160-
| [Azure Monitor Log Analytics](/azure/azure-monitor/logs/log-analytics-overview) | Yes, including Managed HSM | |
161-
| [Azure Data Explorer](/azure/data-explorer/) | Yes | |
162-
| [Azure Data Factory](/azure/data-factory/) | Yes, including Managed HSM | |
163-
| [Azure Data Lake Store](/azure/data-lake-store/) | Yes, RSA 2048-bit | |
164-
| **Containers** | | |
165-
| [Azure Kubernetes Service](/azure/aks/) | Yes, including Managed HSM | |
166-
| [Container Instances](/azure/container-instances/) | Yes | |
167-
| [Container Registry](/azure/container-registry/) | Yes | |
168-
| **Compute** | | |
169-
| [Virtual Machines](/azure/virtual-machines/) | Yes, including Managed HSM | |
170-
| [Virtual Machine Scale Set](/azure/virtual-machine-scale-sets/) | Yes, including Managed HSM | |
171-
| [SAP HANA](/azure/sap/large-instances/hana-overview-architecture) | Yes | |
172-
| [App Service](/azure/app-service/) | Yes\*\*, including Managed HSM | |
173-
| [Automation](/azure/automation/) | Yes | |
174-
| [Azure Functions](/azure/azure-functions/) | Yes\*\*, including Managed HSM | |
175-
| [Azure portal](/azure/azure-portal/) | Yes\*\*, including Managed HSM | |
176-
| [Azure VMware Solution](/azure/azure-vmware/) | Yes, including Managed HSM | |
177-
| [Logic Apps](/azure/logic-apps/) | Yes | |
178-
| [Azure-managed applications](/azure/azure-resource-manager/managed-applications/overview) | Yes\*\*, including Managed HSM | |
179-
| [Service Bus](/azure/service-bus-messaging/) | Yes | |
180-
| [Site Recovery](/azure/site-recovery/) | Yes | |
181-
| **Databases** | | |
182-
| [SQL Server on Virtual Machines](/azure/virtual-machines/windows/sql/) | Yes | |
183-
| [Azure SQL Database](/azure/azure-sql/database/) | Yes, RSA 3072-bit, including Managed HSM | |
184-
| [Azure SQL Managed Instance](/azure/azure-sql/managed-instance/) | Yes, RSA 3072-bit, including Managed HSM | |
185-
| [Azure Database for MariaDB](/azure/mariadb/) | - | |
186-
| [Azure Database for MySQL](/azure/mysql/) | Yes, including Managed HSM | |
187-
| [Azure Database for PostgreSQL](/azure/postgresql/) | Yes, including Managed HSM | |
188-
| [Azure Synapse Analytics (dedicated SQL pool (formerly SQL DW) only)](/azure/synapse-analytics/) | Yes, RSA 3072-bit, including Managed HSM | |
189-
| [SQL Server Stretch Database](/sql/sql-server/stretch-database/) | Yes, RSA 3072-bit | |
190-
| [Table Storage](/azure/storage/tables/) | Yes | |
191-
| [Azure Cosmos DB](/azure/cosmos-db/) | Yes, including Managed HSM | [Configure CMKs (Key Vault)](/azure/cosmos-db/how-to-setup-cmk) and [Configure CMKs (Managed HSM)](/azure/cosmos-db/how-to-setup-customer-managed-keys-mhsm) |
192-
| [Azure Databricks](/azure/databricks/) | Yes, including Managed HSM | |
193-
| [Azure Database Migration Service](/azure/dms/) | N/A\* | |
194-
| **Identity** | | |
195-
| [Microsoft Entra ID](/azure/active-directory/) | - | |
196-
| [Microsoft Entra Domain Services](/azure/active-directory-domain-services/) | Yes | |
197-
| **Integration** | | |
198-
| [Service Bus](/azure/service-bus-messaging/) | Yes | |
199-
| [Event Grid](/azure/event-grid/) | - | |
200-
| [API Management](/azure/api-management/) | - | |
201-
| **IoT Services** | | |
202-
| [IoT Hub](/azure/iot-hub/) | Yes | |
203-
| [IoT Hub Device Provisioning](/azure/iot-dps/) | Yes | |
204-
| **Management and Governance** | | |
205-
| [Azure Managed Grafana](/azure/managed-grafana/) | - | |
206-
| [Azure Site Recovery](/azure/site-recovery/) | - | |
207-
| [Azure Migrate](/azure/migrate/) | Yes | |
208-
| **Media** | | |
209-
| [Media Services](/azure/media-services/) | Yes | |
210-
| **Security** | | |
211-
| [Microsoft Defender for IoT](/azure/defender-for-iot/) | Yes | |
212-
| [Microsoft Sentinel](/azure/sentinel/) | Yes, including Managed HSM | |
213-
| **Storage** | | |
214-
| [Blob Storage](/azure/storage/blobs/) | Yes, including Managed HSM | |
215-
| [Premium Blob Storage](/azure/storage/blobs/) | Yes, including Managed HSM | |
216-
| [Disk Storage](/azure/virtual-machines/disks-types/) | Yes, including Managed HSM | |
217-
| [Ultra Disk Storage](/azure/virtual-machines/disks-types/) | Yes, including Managed HSM | |
218-
| [Managed Disk Storage](/azure/virtual-machines/disks-types/) | Yes, including Managed HSM | |
219-
| [File Storage](/azure/storage/files/) | Yes, including Managed HSM | |
220-
| [File Premium Storage](/azure/storage/files/) | Yes, including Managed HSM | |
221-
| [File Sync](/azure/storage/file-sync/file-sync-introduction) | Yes, including Managed HSM | |
222-
| [Queue Storage](/azure/storage/queues/) | Yes, including Managed HSM | |
223-
| [Data Lake Storage Gen2](/azure/storage/blobs/data-lake-storage-introduction/) | Yes, including Managed HSM | |
224-
| [Avere vFXT](/azure/avere-vfxt/) | - | |
225-
| [Azure Cache for Redis](/azure/azure-cache-for-redis/) | Yes\*\*\*, including Managed HSM | |
226-
| [Azure NetApp Files](/azure/azure-netapp-files/) | Yes, including Managed HSM | |
227-
| [Archive Storage](/azure/storage/blobs/archive-blob) | Yes | |
228-
| [StorSimple](/azure/storsimple/) | Yes | |
229-
| [Azure Backup](/azure/backup/) | Yes, including Managed HSM | |
230-
| [Data Box](/azure/databox/) | - | |
231-
| [Azure Stack Edge](/azure/databox-online/azure-stack-edge-overview/) | Yes | |
232-
| **Other** | | |
233-
| [Azure Data Manager for Energy](/azure/energy-data-services/overview-microsoft-energy-data-services) | Yes | |
131+
## Services supporting customer managed keys (CMKs)
132+
133+
Here are the services that support server-side encryption using customer managed keys:
134+
135+
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
136+
| --- | --- | --- | --- |
137+
| **AI and Machine Learning** | | | |
138+
| [Azure AI Search](/azure/search/) | Yes | | |
139+
| [Azure AI services](/azure/cognitive-services/) | Yes | Yes | |
140+
| [Azure Machine Learning](/azure/machine-learning/) | Yes | | |
141+
| [Content Moderator](/azure/cognitive-services/content-moderator/) | Yes | Yes | |
142+
| [Face](/azure/cognitive-services/face/) | Yes | Yes | |
143+
| [Language Understanding](/azure/cognitive-services/luis/) | Yes | Yes | |
144+
| [Azure OpenAI](/azure/ai-services/openai/) | Yes | Yes | |
145+
| [Personalizer](/azure/cognitive-services/personalizer/) | Yes | Yes | |
146+
| [QnA Maker](/azure/cognitive-services/qnamaker/) | Yes | Yes | |
147+
| [Speech Services](/azure/cognitive-services/speech-service/) | Yes | Yes | |
148+
| [Translator Text](/azure/cognitive-services/translator/) | Yes | Yes | |
149+
| [Power Platform](/power-platform/) | Yes | Yes | |
150+
| [Dataverse](/powerapps/maker/data-platform/) | Yes | Yes | |
151+
| [Dynamics 365](/dynamics365/) | Yes | Yes | |
152+
| **Analytics** | | | |
153+
| [Azure Stream Analytics](/azure/stream-analytics/) | Yes\*\* | Yes | |
154+
| [Event Hubs](/azure/event-hubs/) | Yes | | |
155+
| [Functions](/azure/azure-functions/) | Yes | | |
156+
| [Azure HDInsight](/azure/hdinsight/) | Yes | | |
157+
| [Azure Monitor Application Insights](/azure/azure-monitor/app/app-insights-overview) | Yes | | |
158+
| [Azure Monitor Log Analytics](/azure/azure-monitor/logs/log-analytics-overview) | Yes | Yes | |
159+
| [Azure Data Explorer](/azure/data-explorer/) | Yes | | |
160+
| [Azure Data Factory](/azure/data-factory/) | Yes | Yes | |
161+
| [Azure Data Lake Store](/azure/data-lake-store/) | Yes, RSA 2048-bit | | |
162+
| **Containers** | | | |
163+
| [Azure Kubernetes Service](/azure/aks/) | Yes | Yes | |
164+
| [Container Instances](/azure/container-instances/) | Yes | | |
165+
| [Container Registry](/azure/container-registry/) | Yes | | |
166+
| **Compute** | | | |
167+
| [Virtual Machines](/azure/virtual-machines/) | Yes | Yes | |
168+
| [Virtual Machine Scale Set](/azure/virtual-machine-scale-sets/) | Yes | Yes | |
169+
| [SAP HANA](/azure/sap/large-instances/hana-overview-architecture) | Yes | | |
170+
| [App Service](/azure/app-service/) | Yes\*\* | Yes | |
171+
| [Automation](/azure/automation/) | Yes | | |
172+
| [Azure Functions](/azure/azure-functions/) | Yes\*\* | Yes | |
173+
| [Azure portal](/azure/azure-portal/) | Yes\*\* | Yes | |
174+
| [Azure VMware Solution](/azure/azure-vmware/) | Yes | Yes | |
175+
| [Logic Apps](/azure/logic-apps/) | Yes | | |
176+
| [Azure-managed applications](/azure/azure-resource-manager/managed-applications/overview) | Yes\*\* | Yes | |
177+
| [Service Bus](/azure/service-bus-messaging/) | Yes | | |
178+
| [Site Recovery](/azure/site-recovery/) | Yes | | |
179+
| **Databases** | | | |
180+
| [SQL Server on Virtual Machines](/azure/virtual-machines/windows/sql/) | Yes | | |
181+
| [Azure SQL Database](/azure/azure-sql/database/) | Yes, RSA 3072-bit | Yes | |
182+
| [Azure SQL Managed Instance](/azure/azure-sql/managed-instance/) | Yes, RSA 3072-bit | Yes | |
183+
| [Azure Database for MySQL](/azure/mysql/) | Yes | Yes | |
184+
| [Azure Database for PostgreSQL](/azure/postgresql/) | Yes | Yes | |
185+
| [Azure Synapse Analytics (dedicated SQL pool (formerly SQL DW) only)](/azure/synapse-analytics/) | Yes, RSA 3072-bit | Yes | |
186+
| [SQL Server Stretch Database](/sql/sql-server/stretch-database/) | Yes, RSA 3072-bit | | |
187+
| [Table Storage](/azure/storage/tables/) | Yes | | |
188+
| [Azure Cosmos DB](/azure/cosmos-db/) | Yes | Yes | [Configure CMKs (Key Vault)](/azure/cosmos-db/how-to-setup-cmk) and [Configure CMKs (Managed HSM)](/azure/cosmos-db/how-to-setup-customer-managed-keys-mhsm) |
189+
| [Azure Databricks](/azure/databricks/) | Yes | Yes | |
190+
| [Azure Database Migration Service](/azure/dms/) | N/A\* | | |
191+
| **Identity** | | | |
192+
| [Microsoft Entra ID](/azure/active-directory/) | - | | |
193+
| [Microsoft Entra Domain Services](/azure/active-directory-domain-services/) | Yes | | |
194+
| **Integration** | | | |
195+
| [Service Bus](/azure/service-bus-messaging/) | Yes | | |
196+
| **IoT Services** | | | |
197+
| [IoT Hub](/azure/iot-hub/) | Yes | | |
198+
| [IoT Hub Device Provisioning](/azure/iot-dps/) | Yes | | |
199+
| **Management and Governance** | | | |
200+
| [Azure Migrate](/azure/migrate/) | Yes | | |
201+
| **Media** | | | |
202+
| [Media Services](/azure/media-services/) | Yes | | |
203+
| **Security** | | | |
204+
| [Microsoft Defender for IoT](/azure/defender-for-iot/) | Yes | | |
205+
| [Microsoft Sentinel](/azure/sentinel/) | Yes | Yes | |
206+
| **Storage** | | | |
207+
| [Blob Storage](/azure/storage/blobs/) | Yes | Yes | |
208+
| [Premium Blob Storage](/azure/storage/blobs/) | Yes | Yes | |
209+
| [Disk Storage](/azure/virtual-machines/disks-types/) | Yes | Yes | |
210+
| [Ultra Disk Storage](/azure/virtual-machines/disks-types/) | Yes | Yes | |
211+
| [Managed Disk Storage](/azure/virtual-machines/disks-types/) | Yes | Yes | |
212+
| [File Storage](/azure/storage/files/) | Yes | Yes | |
213+
| [File Premium Storage](/azure/storage/files/) | Yes | Yes | |
214+
| [File Sync](/azure/storage/file-sync/file-sync-introduction) | Yes | Yes | |
215+
| [Queue Storage](/azure/storage/queues/) | Yes | Yes | |
216+
| [Data Lake Storage Gen2](/azure/storage/blobs/data-lake-storage-introduction/) | Yes | Yes | |
217+
| [Azure Cache for Redis](/azure/azure-cache-for-redis/) | Yes\*\* | Yes | |
218+
| [Azure NetApp Files](/azure/azure-netapp-files/) | Yes | Yes | |
219+
| [Archive Storage](/azure/storage/blobs/archive-blob) | Yes | | |
220+
| [StorSimple](/azure/storsimple/) | Yes | | |
221+
| [Azure Backup](/azure/backup/) | Yes | Yes | |
222+
| [Azure Stack Edge](/azure/databox-online/azure-stack-edge-overview/) | Yes | | |
223+
| **Other** | | | |
224+
| [Azure Data Manager for Energy](/azure/energy-data-services/overview-microsoft-energy-data-services) | Yes | | |
234225

235226
\* This service doesn't persist data. Transient caches, if any, are encrypted with a Microsoft key.
236227

0 commit comments

Comments
 (0)