Disk Encryption support

Gerhart Jan 21 Reputation points
2022-09-22T06:54:43.997+00:00

Hello,

we are considering disk encryption with our own keys. What are the options of troubleshooting the potential issues by MS Support Engineer if any operation fail? Does have MS Support engineer access to my Key Vault or keys? What happened if I open a ticket related to the disk encryption?

Thanks

Jan

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
160 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sumarigo-MSFT 43,411 Reputation points Microsoft Employee
    2022-09-30T17:47:04.7+00:00

    @Gerhart Jan Welcome to Microsoft Q&A Forum, Thank you for posting your query here

    Microsoft doesn't have access to the keys Customer(you) is owner and responsible for the key lifecycle. We just provide the key vault as container for the key and also soft delete option but we don't have access to the keys.

    Please let us know if you have any further queries. I’m happy to assist you further.

    ----------

    Please do not forget to 246535-screenshot-2021-12-10-121802.png and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. rafalzak 3,216 Reputation points
    2022-09-22T07:30:34.97+00:00

    Hi @Gerhart Jan ,

    1) You could use Customer Lockbox in order to provide access for MS Engineer so they will be able do some troubleshooting.
    2) The Lockbox do not support access to Key Vault.
    https://learn.microsoft.com/en-us/azure/security/fundamentals/customer-lockbox-overview
    3) They will try to help you solve the problem.

    0 comments No comments