@@ -128,109 +128,100 @@ When server-side encryption using customer-managed keys in customer-controlled h
128
128
- Significant setup, configuration, and ongoing maintenance costs
129
129
- Increased dependency on network availability between the customer datacenter and Azure datacenters.
130
130
131
- ## Supporting services
132
-
133
- The Azure services that support each encryption model:
134
-
135
- | Product, Feature, or Service | Server-Side Using Customer-Managed Key | Documentation |
136
- | --- | --- | --- |
137
- | ** AI and Machine Learning** | | |
138
- | [ Azure AI Search] ( /azure/search/ ) | Yes | |
139
- | [ Azure AI services] ( /azure/cognitive-services/ ) | Yes, including Managed HSM | |
140
- | [ Azure Machine Learning] ( /azure/machine-learning/ ) | Yes | |
141
- | [ Content Moderator] ( /azure/cognitive-services/content-moderator/ ) | Yes, including Managed HSM | |
142
- | [ Face] ( /azure/cognitive-services/face/ ) | Yes, including Managed HSM | |
143
- | [ Language Understanding] ( /azure/cognitive-services/luis/ ) | Yes, including Managed HSM | |
144
- | [ Azure OpenAI] ( /azure/ai-services/openai/ ) | Yes, including Managed HSM | |
145
- | [ Personalizer] ( /azure/cognitive-services/personalizer/ ) | Yes, including Managed HSM | |
146
- | [ QnA Maker] ( /azure/cognitive-services/qnamaker/ ) | Yes, including Managed HSM | |
147
- | [ Speech Services] ( /azure/cognitive-services/speech-service/ ) | Yes, including Managed HSM | |
148
- | [ Translator Text] ( /azure/cognitive-services/translator/ ) | Yes, including Managed HSM | |
149
- | [ Power Platform] ( /power-platform/ ) | Yes, including Managed HSM | |
150
- | [ Dataverse] ( /powerapps/maker/data-platform/ ) | Yes, including Managed HSM | |
151
- | [ Dynamics 365] ( /dynamics365/ ) | Yes, including Managed HSM | |
152
- | ** Analytics** | | |
153
- | [ Azure Stream Analytics] ( /azure/stream-analytics/ ) | Yes\*\* , including Managed HSM | |
154
- | [ Event Hubs] ( /azure/event-hubs/ ) | Yes | |
155
- | [ Functions] ( /azure/azure-functions/ ) | Yes | |
156
- | [ Azure Analysis Services] ( /azure/analysis-services/ ) | - | |
157
- | [ Azure Data Catalog] ( /azure/data-catalog/ ) | - | |
158
- | [ Azure HDInsight] ( /azure/hdinsight/ ) | Yes | |
159
- | [ Azure Monitor Application Insights] ( /azure/azure-monitor/app/app-insights-overview ) | Yes | |
160
- | [ Azure Monitor Log Analytics] ( /azure/azure-monitor/logs/log-analytics-overview ) | Yes, including Managed HSM | |
161
- | [ Azure Data Explorer] ( /azure/data-explorer/ ) | Yes | |
162
- | [ Azure Data Factory] ( /azure/data-factory/ ) | Yes, including Managed HSM | |
163
- | [ Azure Data Lake Store] ( /azure/data-lake-store/ ) | Yes, RSA 2048-bit | |
164
- | ** Containers** | | |
165
- | [ Azure Kubernetes Service] ( /azure/aks/ ) | Yes, including Managed HSM | |
166
- | [ Container Instances] ( /azure/container-instances/ ) | Yes | |
167
- | [ Container Registry] ( /azure/container-registry/ ) | Yes | |
168
- | ** Compute** | | |
169
- | [ Virtual Machines] ( /azure/virtual-machines/ ) | Yes, including Managed HSM | |
170
- | [ Virtual Machine Scale Set] ( /azure/virtual-machine-scale-sets/ ) | Yes, including Managed HSM | |
171
- | [ SAP HANA] ( /azure/sap/large-instances/hana-overview-architecture ) | Yes | |
172
- | [ App Service] ( /azure/app-service/ ) | Yes\*\* , including Managed HSM | |
173
- | [ Automation] ( /azure/automation/ ) | Yes | |
174
- | [ Azure Functions] ( /azure/azure-functions/ ) | Yes\*\* , including Managed HSM | |
175
- | [ Azure portal] ( /azure/azure-portal/ ) | Yes\*\* , including Managed HSM | |
176
- | [ Azure VMware Solution] ( /azure/azure-vmware/ ) | Yes, including Managed HSM | |
177
- | [ Logic Apps] ( /azure/logic-apps/ ) | Yes | |
178
- | [ Azure-managed applications] ( /azure/azure-resource-manager/managed-applications/overview ) | Yes\*\* , including Managed HSM | |
179
- | [ Service Bus] ( /azure/service-bus-messaging/ ) | Yes | |
180
- | [ Site Recovery] ( /azure/site-recovery/ ) | Yes | |
181
- | ** Databases** | | |
182
- | [ SQL Server on Virtual Machines] ( /azure/virtual-machines/windows/sql/ ) | Yes | |
183
- | [ Azure SQL Database] ( /azure/azure-sql/database/ ) | Yes, RSA 3072-bit, including Managed HSM | |
184
- | [ Azure SQL Managed Instance] ( /azure/azure-sql/managed-instance/ ) | Yes, RSA 3072-bit, including Managed HSM | |
185
- | [ Azure Database for MariaDB] ( /azure/mariadb/ ) | - | |
186
- | [ Azure Database for MySQL] ( /azure/mysql/ ) | Yes, including Managed HSM | |
187
- | [ Azure Database for PostgreSQL] ( /azure/postgresql/ ) | Yes, including Managed HSM | |
188
- | [ Azure Synapse Analytics (dedicated SQL pool (formerly SQL DW) only)] ( /azure/synapse-analytics/ ) | Yes, RSA 3072-bit, including Managed HSM | |
189
- | [ SQL Server Stretch Database] ( /sql/sql-server/stretch-database/ ) | Yes, RSA 3072-bit | |
190
- | [ Table Storage] ( /azure/storage/tables/ ) | Yes | |
191
- | [ Azure Cosmos DB] ( /azure/cosmos-db/ ) | Yes, including Managed HSM | [ Configure CMKs (Key Vault)] ( /azure/cosmos-db/how-to-setup-cmk ) and [ Configure CMKs (Managed HSM)] ( /azure/cosmos-db/how-to-setup-customer-managed-keys-mhsm ) |
192
- | [ Azure Databricks] ( /azure/databricks/ ) | Yes, including Managed HSM | |
193
- | [ Azure Database Migration Service] ( /azure/dms/ ) | N/A\* | |
194
- | ** Identity** | | |
195
- | [ Microsoft Entra ID] ( /azure/active-directory/ ) | - | |
196
- | [ Microsoft Entra Domain Services] ( /azure/active-directory-domain-services/ ) | Yes | |
197
- | ** Integration** | | |
198
- | [ Service Bus] ( /azure/service-bus-messaging/ ) | Yes | |
199
- | [ Event Grid] ( /azure/event-grid/ ) | - | |
200
- | [ API Management] ( /azure/api-management/ ) | - | |
201
- | ** IoT Services** | | |
202
- | [ IoT Hub] ( /azure/iot-hub/ ) | Yes | |
203
- | [ IoT Hub Device Provisioning] ( /azure/iot-dps/ ) | Yes | |
204
- | ** Management and Governance** | | |
205
- | [ Azure Managed Grafana] ( /azure/managed-grafana/ ) | - | |
206
- | [ Azure Site Recovery] ( /azure/site-recovery/ ) | - | |
207
- | [ Azure Migrate] ( /azure/migrate/ ) | Yes | |
208
- | ** Media** | | |
209
- | [ Media Services] ( /azure/media-services/ ) | Yes | |
210
- | ** Security** | | |
211
- | [ Microsoft Defender for IoT] ( /azure/defender-for-iot/ ) | Yes | |
212
- | [ Microsoft Sentinel] ( /azure/sentinel/ ) | Yes, including Managed HSM | |
213
- | ** Storage** | | |
214
- | [ Blob Storage] ( /azure/storage/blobs/ ) | Yes, including Managed HSM | |
215
- | [ Premium Blob Storage] ( /azure/storage/blobs/ ) | Yes, including Managed HSM | |
216
- | [ Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes, including Managed HSM | |
217
- | [ Ultra Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes, including Managed HSM | |
218
- | [ Managed Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes, including Managed HSM | |
219
- | [ File Storage] ( /azure/storage/files/ ) | Yes, including Managed HSM | |
220
- | [ File Premium Storage] ( /azure/storage/files/ ) | Yes, including Managed HSM | |
221
- | [ File Sync] ( /azure/storage/file-sync/file-sync-introduction ) | Yes, including Managed HSM | |
222
- | [ Queue Storage] ( /azure/storage/queues/ ) | Yes, including Managed HSM | |
223
- | [ Data Lake Storage Gen2] ( /azure/storage/blobs/data-lake-storage-introduction/ ) | Yes, including Managed HSM | |
224
- | [ Avere vFXT] ( /azure/avere-vfxt/ ) | - | |
225
- | [ Azure Cache for Redis] ( /azure/azure-cache-for-redis/ ) | Yes\*\*\* , including Managed HSM | |
226
- | [ Azure NetApp Files] ( /azure/azure-netapp-files/ ) | Yes, including Managed HSM | |
227
- | [ Archive Storage] ( /azure/storage/blobs/archive-blob ) | Yes | |
228
- | [ StorSimple] ( /azure/storsimple/ ) | Yes | |
229
- | [ Azure Backup] ( /azure/backup/ ) | Yes, including Managed HSM | |
230
- | [ Data Box] ( /azure/databox/ ) | - | |
231
- | [ Azure Stack Edge] ( /azure/databox-online/azure-stack-edge-overview/ ) | Yes | |
232
- | ** Other** | | |
233
- | [ Azure Data Manager for Energy] ( /azure/energy-data-services/overview-microsoft-energy-data-services ) | Yes | |
131
+ ## Services supporting customer managed keys (CMKs)
132
+
133
+ Here are the services that support server-side encryption using customer managed keys:
134
+
135
+ | Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
136
+ | --- | --- | --- | --- |
137
+ | ** AI and Machine Learning** | | | |
138
+ | [ Azure AI Search] ( /azure/search/ ) | Yes | | |
139
+ | [ Azure AI services] ( /azure/cognitive-services/ ) | Yes | Yes | |
140
+ | [ Azure Machine Learning] ( /azure/machine-learning/ ) | Yes | | |
141
+ | [ Content Moderator] ( /azure/cognitive-services/content-moderator/ ) | Yes | Yes | |
142
+ | [ Face] ( /azure/cognitive-services/face/ ) | Yes | Yes | |
143
+ | [ Language Understanding] ( /azure/cognitive-services/luis/ ) | Yes | Yes | |
144
+ | [ Azure OpenAI] ( /azure/ai-services/openai/ ) | Yes | Yes | |
145
+ | [ Personalizer] ( /azure/cognitive-services/personalizer/ ) | Yes | Yes | |
146
+ | [ QnA Maker] ( /azure/cognitive-services/qnamaker/ ) | Yes | Yes | |
147
+ | [ Speech Services] ( /azure/cognitive-services/speech-service/ ) | Yes | Yes | |
148
+ | [ Translator Text] ( /azure/cognitive-services/translator/ ) | Yes | Yes | |
149
+ | [ Power Platform] ( /power-platform/ ) | Yes | Yes | |
150
+ | [ Dataverse] ( /powerapps/maker/data-platform/ ) | Yes | Yes | |
151
+ | [ Dynamics 365] ( /dynamics365/ ) | Yes | Yes | |
152
+ | ** Analytics** | | | |
153
+ | [ Azure Stream Analytics] ( /azure/stream-analytics/ ) | Yes\*\* | Yes | |
154
+ | [ Event Hubs] ( /azure/event-hubs/ ) | Yes | | |
155
+ | [ Functions] ( /azure/azure-functions/ ) | Yes | | |
156
+ | [ Azure HDInsight] ( /azure/hdinsight/ ) | Yes | | |
157
+ | [ Azure Monitor Application Insights] ( /azure/azure-monitor/app/app-insights-overview ) | Yes | | |
158
+ | [ Azure Monitor Log Analytics] ( /azure/azure-monitor/logs/log-analytics-overview ) | Yes | Yes | |
159
+ | [ Azure Data Explorer] ( /azure/data-explorer/ ) | Yes | | |
160
+ | [ Azure Data Factory] ( /azure/data-factory/ ) | Yes | Yes | |
161
+ | [ Azure Data Lake Store] ( /azure/data-lake-store/ ) | Yes, RSA 2048-bit | | |
162
+ | ** Containers** | | | |
163
+ | [ Azure Kubernetes Service] ( /azure/aks/ ) | Yes | Yes | |
164
+ | [ Container Instances] ( /azure/container-instances/ ) | Yes | | |
165
+ | [ Container Registry] ( /azure/container-registry/ ) | Yes | | |
166
+ | ** Compute** | | | |
167
+ | [ Virtual Machines] ( /azure/virtual-machines/ ) | Yes | Yes | |
168
+ | [ Virtual Machine Scale Set] ( /azure/virtual-machine-scale-sets/ ) | Yes | Yes | |
169
+ | [ SAP HANA] ( /azure/sap/large-instances/hana-overview-architecture ) | Yes | | |
170
+ | [ App Service] ( /azure/app-service/ ) | Yes\*\* | Yes | |
171
+ | [ Automation] ( /azure/automation/ ) | Yes | | |
172
+ | [ Azure Functions] ( /azure/azure-functions/ ) | Yes\*\* | Yes | |
173
+ | [ Azure portal] ( /azure/azure-portal/ ) | Yes\*\* | Yes | |
174
+ | [ Azure VMware Solution] ( /azure/azure-vmware/ ) | Yes | Yes | |
175
+ | [ Logic Apps] ( /azure/logic-apps/ ) | Yes | | |
176
+ | [ Azure-managed applications] ( /azure/azure-resource-manager/managed-applications/overview ) | Yes\*\* | Yes | |
177
+ | [ Service Bus] ( /azure/service-bus-messaging/ ) | Yes | | |
178
+ | [ Site Recovery] ( /azure/site-recovery/ ) | Yes | | |
179
+ | ** Databases** | | | |
180
+ | [ SQL Server on Virtual Machines] ( /azure/virtual-machines/windows/sql/ ) | Yes | | |
181
+ | [ Azure SQL Database] ( /azure/azure-sql/database/ ) | Yes, RSA 3072-bit | Yes | |
182
+ | [ Azure SQL Managed Instance] ( /azure/azure-sql/managed-instance/ ) | Yes, RSA 3072-bit | Yes | |
183
+ | [ Azure Database for MySQL] ( /azure/mysql/ ) | Yes | Yes | |
184
+ | [ Azure Database for PostgreSQL] ( /azure/postgresql/ ) | Yes | Yes | |
185
+ | [ Azure Synapse Analytics (dedicated SQL pool (formerly SQL DW) only)] ( /azure/synapse-analytics/ ) | Yes, RSA 3072-bit | Yes | |
186
+ | [ SQL Server Stretch Database] ( /sql/sql-server/stretch-database/ ) | Yes, RSA 3072-bit | | |
187
+ | [ Table Storage] ( /azure/storage/tables/ ) | Yes | | |
188
+ | [ Azure Cosmos DB] ( /azure/cosmos-db/ ) | Yes | Yes | [ Configure CMKs (Key Vault)] ( /azure/cosmos-db/how-to-setup-cmk ) and [ Configure CMKs (Managed HSM)] ( /azure/cosmos-db/how-to-setup-customer-managed-keys-mhsm ) |
189
+ | [ Azure Databricks] ( /azure/databricks/ ) | Yes | Yes | |
190
+ | [ Azure Database Migration Service] ( /azure/dms/ ) | N/A\* | | |
191
+ | ** Identity** | | | |
192
+ | [ Microsoft Entra ID] ( /azure/active-directory/ ) | - | | |
193
+ | [ Microsoft Entra Domain Services] ( /azure/active-directory-domain-services/ ) | Yes | | |
194
+ | ** Integration** | | | |
195
+ | [ Service Bus] ( /azure/service-bus-messaging/ ) | Yes | | |
196
+ | ** IoT Services** | | | |
197
+ | [ IoT Hub] ( /azure/iot-hub/ ) | Yes | | |
198
+ | [ IoT Hub Device Provisioning] ( /azure/iot-dps/ ) | Yes | | |
199
+ | ** Management and Governance** | | | |
200
+ | [ Azure Migrate] ( /azure/migrate/ ) | Yes | | |
201
+ | ** Media** | | | |
202
+ | [ Media Services] ( /azure/media-services/ ) | Yes | | |
203
+ | ** Security** | | | |
204
+ | [ Microsoft Defender for IoT] ( /azure/defender-for-iot/ ) | Yes | | |
205
+ | [ Microsoft Sentinel] ( /azure/sentinel/ ) | Yes | Yes | |
206
+ | ** Storage** | | | |
207
+ | [ Blob Storage] ( /azure/storage/blobs/ ) | Yes | Yes | |
208
+ | [ Premium Blob Storage] ( /azure/storage/blobs/ ) | Yes | Yes | |
209
+ | [ Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes | Yes | |
210
+ | [ Ultra Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes | Yes | |
211
+ | [ Managed Disk Storage] ( /azure/virtual-machines/disks-types/ ) | Yes | Yes | |
212
+ | [ File Storage] ( /azure/storage/files/ ) | Yes | Yes | |
213
+ | [ File Premium Storage] ( /azure/storage/files/ ) | Yes | Yes | |
214
+ | [ File Sync] ( /azure/storage/file-sync/file-sync-introduction ) | Yes | Yes | |
215
+ | [ Queue Storage] ( /azure/storage/queues/ ) | Yes | Yes | |
216
+ | [ Data Lake Storage Gen2] ( /azure/storage/blobs/data-lake-storage-introduction/ ) | Yes | Yes | |
217
+ | [ Azure Cache for Redis] ( /azure/azure-cache-for-redis/ ) | Yes\*\* | Yes | |
218
+ | [ Azure NetApp Files] ( /azure/azure-netapp-files/ ) | Yes | Yes | |
219
+ | [ Archive Storage] ( /azure/storage/blobs/archive-blob ) | Yes | | |
220
+ | [ StorSimple] ( /azure/storsimple/ ) | Yes | | |
221
+ | [ Azure Backup] ( /azure/backup/ ) | Yes | Yes | |
222
+ | [ Azure Stack Edge] ( /azure/databox-online/azure-stack-edge-overview/ ) | Yes | | |
223
+ | ** Other** | | | |
224
+ | [ Azure Data Manager for Energy] ( /azure/energy-data-services/overview-microsoft-energy-data-services ) | Yes | | |
234
225
235
226
\* This service doesn't persist data. Transient caches, if any, are encrypted with a Microsoft key.
236
227
0 commit comments