Manage keys and secrets in Azure Key Vault

Intermediate
Security Engineer
Azure Key Vault
Azure

Manage the security lifecycle of cryptographic keys and secrets in Azure Key Vault. Configure HSM-backed keys, implement Bring Your Own Key (BYOK) for regulatory scenarios, set up automated key rotation, and build zero-downtime secret rotation using dual-credential patterns.

Learning objectives

After completing this module, you'll be able to:

  • Create and manage cryptographic keys, including HSM-protected and BYOK scenarios
  • Configure automated key rotation policies to minimize cryptographic exposure risk
  • Build zero-downtime secret rotation using dual-credential and automated rotation patterns

Prerequisites

  • Azure Key Vault deployed and secured with access controls configured
  • Understanding of Azure RBAC and managed identities
  • Familiarity with cryptographic concepts including keys and secrets

Get started with Azure

Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.