You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|[Azure Synapse Analytics](/azure/synapse-analytics/)| Yes (RSA 3072-bit) | Yes |[Configure encryption at rest with customer-managed keys](/azure/synapse-analytics/security/workspaces-encryption)|
52
52
|[Microsoft Fabric](/fabric)| Yes ||[Customer-managed key (CMK) encryption and Microsoft Fabric](/fabric/security/security-scenario#customer-managed-key-cmk-encryption-and-microsoft-fabric)|
53
53
|[Power BI Embedded](/power-bi)| Yes ||[Using your own key for Power BI encryption (Preview)](/power-bi/enterprise/service-encryption-byok)|
@@ -65,11 +65,11 @@ The following services support server-side encryption with customer managed keys
65
65
66
66
| Product, Feature, or Service | Key Vault | Managed HSM | Documentation |
67
67
|---|---|---|---|---|
68
-
|[App Service](/azure/app-service/)| Yes\*\*| Yes |[Configure customer-managed keys for App Service](/azure/app-service/configure-encrypt-at-rest-using-cmk)|
69
-
|[Azure Functions](/azure/azure-functions/)| Yes\*\*| Yes |[Configure customer-managed keys for Azure Functions](/azure/azure-functions/configure-encrypt-at-rest-using-cmk)|
68
+
|[App Service](/azure/app-service/)| Yes\*| Yes |[Configure customer-managed keys for App Service](/azure/app-service/configure-encrypt-at-rest-using-cmk)|
69
+
|[Azure Functions](/azure/azure-functions/)| Yes\*| Yes |[Configure customer-managed keys for Azure Functions](/azure/azure-functions/configure-encrypt-at-rest-using-cmk)|
70
70
|[Azure HPC Cache](/azure/hpc-cache/)| Yes ||[Use customer-managed keys with HPC Cache](/azure/hpc-cache/customer-keys)|
@@ -86,7 +86,6 @@ The following services support server-side encryption with customer managed keys
86
86
|[Azure Database for MySQL - Single Server](/azure/mysql/single-server/)| Yes ||[Azure Database for MySQL data encryption with a customer-managed key](/previous-versions/azure/mysql/single-server/concepts-data-encryption-mysql)|
87
87
|[Azure Database for PostgreSQL - Flexible Server](/azure/postgresql/flexible-server/)| Yes ||[Data encryption with customer-managed keys in Azure Database for PostgreSQL - Flexible Server](/azure/postgresql/flexible-server/concepts-data-encryption)|
88
88
|[Azure Database for PostgreSQL - Single Server](/azure/postgresql/)| Yes | Yes |[Data encryption with customer-managed keys in Azure Database for PostgreSQL - Single Server](/previous-versions/azure/postgresql/single-server/concepts-data-encryption-postgresql)|
89
-
|[Azure Database Migration Service](/azure/dms/)| N/A\*||[What is Azure Database Migration Service?](/azure/dms/dms-overview)|
90
89
|[Azure Managed Instance for Apache Cassandra](/azure/managed-instance-apache-cassandra/)| Yes ||[Configure customer-managed keys for encryption](/azure/managed-instance-apache-cassandra/customer-managed-keys)|
91
90
|[Azure SQL Database](/azure/azure-sql/database/)| Yes (RSA 3072-bit) | Yes |[Bring your own key (BYOK) support for Transparent Data Encryption (TDE)](/azure/azure-sql/database/transparent-data-encryption-byok-overview)|
92
91
|[Azure SQL Managed Instance](/azure/azure-sql/managed-instance/)| Yes (RSA 3072-bit) | Yes |[Bring your own key (BYOK) support for Transparent Data Encryption (TDE)](/azure/azure-sql/database/transparent-data-encryption-byok-overview)|
@@ -148,7 +147,7 @@ The following services support server-side encryption with customer managed keys
148
147
|---|---|---|---|---|
149
148
|[Archive Storage](/azure/storage/blobs/archive-blob)| Yes ||[Customer-managed keys for Azure Storage encryption](/azure/storage/common/customer-managed-keys-overview)|
150
149
|[Azure Backup](/azure/backup/)| Yes | Yes |[Encrypt backup data using customer-managed keys](/azure/backup/encryption-at-rest-with-cmk)|
151
-
|[Azure Cache for Redis](/azure/azure-cache-for-redis/)| Yes\*\*\*| Yes |[Configure disk encryption for Azure Cache for Redis instances using customer managed keys](/azure/azure-cache-for-redis/cache-how-to-encryption)|
150
+
|[Azure Cache for Redis](/azure/azure-cache-for-redis/)| Yes\*\*| Yes |[Configure disk encryption for Azure Cache for Redis instances using customer managed keys](/azure/azure-cache-for-redis/cache-how-to-encryption)|
152
151
|[Azure Data Box](/azure/databox/)| Yes ||[Use a customer-managed key to secure your Data Box](/azure/databox/data-box-customer-managed-encryption-key-portal)|
@@ -171,13 +170,12 @@ The following services support server-side encryption with customer managed keys
171
170
172
171
## Caveats
173
172
174
-
\* This service doesn't persist data. Transient caches, if any, are encrypted with a Microsoft key.
173
+
\* This service supports storing data in your own Key Vault, Storage Account, or other data persisting service that already supports Server-Side Encryption with Customer-Managed Key.
175
174
176
-
\*\* This service supports storing data in your own Key Vault, Storage Account, or other data persisting service that already supports Server-Side Encryption with Customer-Managed Key.
177
-
178
-
\*\*\* Any transient data stored temporarily on disk such as pagefiles or swap files are encrypted with a Microsoft key (all tiers) or a customer-managed key (using the Enterprise and Enterprise Flash tiers). For more information, see [Configure disk encryption in Azure Cache for Redis](../../azure-cache-for-redis/cache-how-to-encryption.md).
175
+
\*\* Any transient data stored temporarily on disk such as pagefiles or swap files are encrypted with a Microsoft key (all tiers) or a customer-managed key (using the Enterprise and Enterprise Flash tiers). For more information, see [Configure disk encryption in Azure Cache for Redis](../../azure-cache-for-redis/cache-how-to-encryption.md).
179
176
180
177
## Related content
181
178
179
+
-[Data encryption models in Microsoft Azure](encryption-models.md)
182
180
-[How encryption is used in Azure](encryption-overview.md)
0 commit comments