Skip to content

Commit ea806e9

Browse files
committed
Added steps and images
1 parent 5619ac9 commit ea806e9

File tree

1 file changed

+13
-5
lines changed

1 file changed

+13
-5
lines changed

articles/databox/data-box-customer-managed-encryption-key-portal.md

Lines changed: 13 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -46,15 +46,15 @@ Configuring customer-managed key for your Azure Data Box is optional. By default
4646

4747
![Choose encryption option](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-2.png)
4848

49-
3. Select encryption type as **Customer managed key**. After you have selected the customer-managed key, **Select key vault and a key**.
49+
3. Select encryption type as **Customer managed key**. After you have selected the customer-managed key, **Select a key vault and key**.
5050

5151
![Select customer-managed key](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-3.png)
5252

5353
5. In the **Select key from Azure Key Vault** blade, the subscription is automatically populated. For **Key vault**, you can select an existing key vault from the dropdown list.
5454

5555
![Create new Azure Key Vault](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-31.png)
5656

57-
You can also select **Create new** to create a new key vault. In the **Create key vault blade**, enter the resource group and the key vault name. Accept all other defaults. Select **Review + Create**.
57+
You can also select **Create new** to create a new key vault. In the **Create key vault blade**, enter the resource group and the key vault name. Ensure that the **Soft delete** and **Purge protection** are enabled. Accept all other defaults. Select **Review + Create**.
5858

5959
![Create new Azure Key Vault](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-4.png)
6060

@@ -66,23 +66,31 @@ Configuring customer-managed key for your Azure Data Box is optional. By default
6666

6767
![Create new key in Azure Key Vault](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-6.png)
6868

69-
9. If you want to create a new key vault, select **Create new** to create a key. RSA key size can be 2048 or greater.
69+
9. If you want to create a new key, select **Create new** to create a key. RSA key size can be 2048 or greater.
7070

7171
![Create new key in Azure Key Vault](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-61.png)
7272

73-
10. Provide the name for your key, accept the other defaults, and select **Create**. You are notified that a key is created in your key vault.
73+
10. Provide the name for your key, accept the other defaults, and select **Create**.
7474

7575
![Create new key](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-7.png)
7676

7777

78-
11. Select the **Version** and then choose **Select**.
78+
11. You are notified that a key is created in your key vault. Select the **Version** and then choose **Select**.
7979

8080
![New key created in key vault](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-8.png)
8181

8282
12. In the **Encryption type** pane, you can see the key vault and the key selected for your customer-managed key.
8383

8484
![Key and key vault for customer-managed key](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-9.png)
8585

86+
13. Save the key.
87+
88+
![Save customer-managed key](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-10.png)
89+
90+
The key URL is displayed under **Encryption type**.
91+
92+
![Customer-managed key URL](./media/data-box-customer-managed-encryption-key-portal/customer-managed-key-11.png)
93+
8694
> [!IMPORTANT]
8795
> You can disable Microsoft managed key and move to customer-managed key at any stage of the Data Box order. However, once you have created the customer-managed key, you cannot disable the key.
8896

0 commit comments

Comments
 (0)