Compliance level -Azure Platform Managed Keys ?

MS Techie 2,701 Reputation points
2023-04-21T13:27:29.04+00:00

In Azure portal, at the time of provisioning Azure VM , for the Azure disks, we select the default option of Platform Managed Keys. Now i understand that if we are using software-based Azure Key vault for the Customer Managed Keys , then compliance is FIPS 140-2 Level 1 https://learn.microsoft.com/en-us/azure/key-vault/keys/about-keys#compliance Please let me know the compliance level of Platform Managed Keys for Azure Disks ? Is it FIPS 140-2 Level 1 for Platform Managed Keys ?

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
175 questions
{count} vote

1 answer

Sort by: Most helpful
  1. Sumarigo-MSFT 47,106 Reputation points Microsoft Employee
    2023-04-30T15:54:57.4166667+00:00

    @MS Techie Apologies for the delay response!

    Microsoft Managed Key Encryption Keys are FIPS 140 level 1. For level 2 protection, customer can opt for customer-managed keys Customer-managed keys for account encryption - Azure Storage | Microsoft Learn. Managed HSM provides level 3 protection.

    Typically, we do not share insights into implementation details on data encryption or details of policy and procedures. You can steer your customers to our compliance and certification documentation here (Microsoft Trust Center Overview | Microsoft Trust Center).

    You want to audit yourself, which is an expensive task, we offer the Right to Audit (R2A) program. You can reach support for more information.
    https://www.microsoft.com/en-us/security/business/services/compliance-program-microsoft-cloud

    Additional information: Licensing Resources and Documents

    Please let us know if you have any further queries. I’m happy to assist you further.


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.