Customer Managed Keys for Azure VMware Solution
Azure VMware Solution encryption with customer-managed keys is now Generally Available. Customer-managed keys give customers maximum control over their encrypted vSAN data on Azure VMware Solution. With this feature, customers can use Azure Key Vault to generate customer managed keys and centralize the key management process.
Azure VMware Solution is a VMware validated first party Azure service from Microsoft that provides private clouds containing VMware vSphere clusters built from dedicated bare-metal Azure infrastructure. It enables customers to leverage their existing investments in VMware skills and tools, allowing them to focus on developing and running their VMware-based workloads on Azure.
Azure VMware Solution provides default data at rest encryption for private cloud’s vSAN datastore, and it is performed with service-managed keys, automatically and transparently managed by Microsoft. However, many industries require data that not only encrypted data at rest but do so by using encryption keys that customers have full control over as per regulations and compliance requirement. Customer-managed keys don’t disable default vSAN datastore encryption. Instead, they add a second layer of encryption on top of the default one. This means that customer-managed keys also deliver double encryption, a feature that is sometimes part of the same compliance requirements.
Azure VMware Solution customers need to enable system-assigned managed identity on their private cloud to access keys within customer owned Azure Key Vault. A user with required permission on Azure Key Vault must first grant Get, wrap key, and unwrap key permissions to private cloud managed identity. Customer can revoke access anytime by removing Azure VMware Solution’s access to customer-owned Azure Key Vault or disabling keys used for private cloud encryption, making it impossible for Azure VMware Solution to read or write any data within customer’s private cloud. Moreover, customers can use Azure Key Vault monitoring to ensure only Azure VMware Solution is accessing keys.
Benefits
- Full control of data access via the ability to remove the key and make the private cloud data inaccessible.
- Full control over the key lifecycle, including rotation of the key to aligning with corporate policies.
- Central management and organization of keys in Azure Key Vault
If you are interested in the Customer-managed Key for Azure VMware Solution, please use these resources to learn more about the service:
- How to Doc: Configure customer-managed key encryption at rest in Azure VMware Solution - Azure VMware Solution | Microsoft Learn
- Create Azure Key Vault: Quickstart - Create an Azure Key Vault with the Azure portal | Microsoft Learn
- Configure Networking for Azure Key Vault: How to configure Azure Key Vault networking configuration | Microsoft Learn
- Homepage: Azure VMware Solution | Microsoft Azure
- Learn: Run VMware resources on Azure VMware Solution Training
- Documentation: Azure VMware Solution
Author Bio
Rahi Patel is a Senior Technical Program Manager in the Azure VMware Solution product group at Microsoft. His background is in infrastructure architecture with extensive experience across all facets of the enterprise, public cloud & service provider spaces, including digital transformation and the business, enterprise, and technology architecture stacks.
Published on:
Learn moreWe can help you with Customer Managed Keys for Azure VMware Solution
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
VMware HCX Design with Azure VMware Solution
Overview VMware HCX is one of the Azure VMware Solution components that generates a large number of service requests from our customers. The A...
Azure Backup and DR: Cross-Region Restore - Exploring Solutions
Azure Backup and DR: Cross-Region Restore - Exploring Solutions When building a Disaster Recovery (DR) plan, customers often face chall...
Microsoft is headed to VMware Explore 2024 in Barcelona!
Microsoft is headed to VMware Explore 2024 in Barcelona! If you want to know about running VCF Private Clouds in Azure, the work we ar...
IBM Power Virtual Server and Microsoft Azure Multi-cloud Integration Patterns
IBM Power Virtual Server and Microsoft Azure Multi-cloud Integration Patterns &nbs...
Enhancing Disaster Recovery and Ransomware Protection with Azure VMware Solution and JetStream
Enhancing Disaster Recovery and Ransomware Protection with Azure VMware Solution and JetStream Software Disaster Recovery (DR) ...
Microsoft is headed to VMware Explore 2024 in Las Vegas
If you want to know about Azure, the work we are doing in partnership with VMware by Broadcom, or have a conversation about your VMwar...
Azure VMware Solution using a public IP down to the NSX-T Edge; configure SNAT, No-SNAT & DNAT
Azure VMware Solution How To Series: Configuring NSX-T SNAT, No-SNAT & DNAT rules Overview Requirements Lab Environment NAT Rules K...
Azure VMware Solution now available in India Central
Azure VMware Solution has expanded its reach and is now available in India Central, marking it as the 33rd Azure region where this particular ...
Azure Migrate - Build 2024 Announcements
Microsoft Build introduced exciting new announcements for Azure Migrate. Cost optimization remains a top priority for customers when selecting...
Azure VMware Solution - Using Log Analytics With NSX-T Firewall Logs
Azure VMware Solution How To Series: Monitoring Azure VMware Solution Overview Requirements Lab Environment Tagging & Groups Kusto ...