Loading...

Customer Managed Keys for Azure VMware Solution

Customer Managed Keys for Azure VMware Solution

Azure VMware Solution encryption with customer-managed keys is now Generally Available. Customer-managed keys give customers maximum control over their encrypted vSAN data on Azure VMware Solution. With this feature, customers can use Azure Key Vault to generate customer managed keys and centralize the key management process.

 

Azure VMware Solution is a VMware validated first party Azure service from Microsoft that provides private clouds containing VMware vSphere clusters built from dedicated bare-metal Azure infrastructure. It enables customers to leverage their existing investments in VMware skills and tools, allowing them to focus on developing and running their VMware-based workloads on Azure.

 

Azure VMware Solution provides default data at rest encryption for private cloud’s vSAN datastore, and it is performed with service-managed keys, automatically and transparently managed by Microsoft. However, many industries require data that not only encrypted data at rest but do so by using encryption keys that customers have full control over as per regulations and compliance requirement. Customer-managed keys don’t disable default vSAN datastore encryption. Instead, they add a second layer of encryption on top of the default one. This means that customer-managed keys also deliver double encryption, a feature that is sometimes part of the same compliance requirements.

 

RahiPatel_0-1678309754141.png

 

Azure VMware Solution customers need to enable system-assigned managed identity on their private cloud to access keys within customer owned Azure Key Vault. A user with required permission on Azure Key Vault must first grant Get, wrap key, and unwrap key permissions to private cloud managed identity. Customer can revoke access anytime by removing Azure VMware Solution’s access to customer-owned Azure Key Vault or disabling keys used for private cloud encryption, making it impossible for Azure VMware Solution to read or write any data within customer’s private cloud. Moreover, customers can use Azure Key Vault monitoring to ensure only Azure VMware Solution is accessing keys.

 

Benefits

  • Full control of data access via the ability to remove the key and make the private cloud data inaccessible.
  • Full control over the key lifecycle, including rotation of the key to aligning with corporate policies.
  • Central management and organization of keys in Azure Key Vault

 

 

If you are interested in the Customer-managed Key for Azure VMware Solution, please use these resources to learn more about the service:

 

Author Bio

Rahi Patel is a Senior Technical Program Manager in the Azure VMware Solution product group at Microsoft. His background is in infrastructure architecture with extensive experience across all facets of the enterprise, public cloud & service provider spaces, including digital transformation and the business, enterprise, and technology architecture stacks. 

Published on:

Learn more
Azure Migration and Modernization Blog articles
Azure Migration and Modernization Blog articles

Azure Migration and Modernization Blog articles

Share post:

Related posts

Introducing Azure HorizonDB - PostgreSQL

Run enterprise Postgres workloads on Azure HorizonDB with around 3x the throughput of self-managed deployments — zone-resilient by default, no...

1 day ago

Azure DevOps and GitHub: Journeying into the AI Era

AI is changing how software gets planned, built, and reviewed. As teams adopt agentic development, the platform underneath those workflows mat...

2 days ago

Introducing azure-functions-skills: An AI-Era Workspace for Azure Functions (Preview)

azure-functions-skills gives GitHub Copilot CLI, Claude Code, Codex CLI, and VS Code the skills, MCP configuration, hooks, and instructions ne...

2 days ago

Announcing the Public Preview of Integrated Embeddings in Azure Cosmos DB: Build AI Apps With Embeddings That Stay in Sync

AI applications built on Azure Cosmos DB depend on embeddings for grounded results. Keeping them in sync with your data is the hard part: it m...

2 days ago

Introducing OmniVec: An Open-Source Embedding Platform for AI Apps on Azure

Today we are open-sourcing OmniVec, a platform for building and operating the embedding pipelines that keep the vector representation of your ...

2 days ago

Azure Cosmos DB All Versions and Deletes Change Feed Mode is Now Generally Available

Modern applications don’t just write data and move on. They react to it. A new order triggers an inventory update. A profile change sync...

2 days ago

Change Partition Keys in Azure Cosmos DB is Now Generally Available

We’re excited to announce the general availability of Change Partition Key in Azure Cosmos DB for NoSQL, now with online copy support. Y...

2 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy