Skip to content

Commit f9ca2c5

Browse files
committed
update infra encryption with note
1 parent 9d456ec commit f9ca2c5

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

articles/storage/common/infrastructure-encryption-enable.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,9 @@ Service-level encryption supports the use of either Microsoft-managed keys or cu
2424

2525
To doubly encrypt your data, you must first create a storage account or an encryption scope that is configured for infrastructure encryption. This article describes how to enable infrastructure encryption.
2626

27+
> [!IMPORTANT]
28+
> Infrastructure encryption is recommended for scenarios where doubly encrypting data is necessary for compliance requirements. For most other scenarios, Azure Storage encryption provides a sufficiently powerful encryption algorithm, and there is unlikely to be a benefit to using infrastructure encryption.
29+
2730
## Create an account with infrastructure encryption enabled
2831

2932
To enable infrastructure encryption for a storage account, you must configure a storage account to use infrastructure encryption at the time that you create the account. Infrastructure encryption cannot be enabled or disabled after the account has been created. The storage account must be of type general-purpose v2 or premium block blob.

0 commit comments

Comments
 (0)