Azure Keyvault - Microsoft Support access to keys and secrets

Ahsan Munim 25 Reputation points
2023-03-20T08:51:07.29+00:00

Hi,

It has been mentioned in the Enhance data protection and compliance that "With Key Vault, Microsoft doesn’t see or extract your keys. " (https://azure.microsoft.com/en-us/products/key-vaul).

My question, does this apply as well if an organization seeks support from Microsoft? if Microsoft is able to extract or see our keys by providing consent to MS, what is the procedure in this?

Another question, without enabling purge protection or soft delete (I believe purge protection is default already) but yeah if the key vault has been deleted for a number of days exceeding the protection. Can Microsoft restore the azure keyvault with the keys and secret intact?

We are asking this question, coz in our country there is a standard that needs to be met in order to migrate certain important data to the cloud.

thanks for looking into this :)

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,100 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 33,706 Reputation points Microsoft Employee
    2023-03-21T22:16:51.4633333+00:00

    Hi @Ahsan ,

    1.) Does this apply as well if an organization seeks support from Microsoft? If Microsoft is able to extract or see our keys by providing consent to MS, what is the procedure in this? This applies even if the organization seeks support from Microsoft. We still cannot see or extract your keys. Our official statement says,

    “Key Vault is designed, deployed and operated such that Microsoft and its agents are precluded from accessing, using or extracting any data stored in the service, including cryptographic keys. The Key Vault team explicitly does not have operating procedures for granting such access to Microsoft and its agents, even if authorized by a customer.

    Azure Key Vault and Azure Key Vault Managed HSM are designed, deployed and operated such that Microsoft and its agents are precluded from accessing, using or extracting any data stored in the service, including cryptographic keys.

    Customer keys that are securely created and/or securely imported into the HSM devices, unless set otherwise by the customer, are not marked extractable and are never visible in plaintext to Microsoft systems, employees, or our agents.

    The Key Vault team explicitly does not have operating procedures for granting such access to Microsoft and its agents, even if authorized by a customer.

    We will not attempt to defeat customer-controlled encryption features like Azure Key Vault or Azure Key Vault Managed HSM. If faced with a legal demand to do so, we would challenge such a demand on any lawful basis, consistent with our customer commitments as outlined in this blog.

    (Azure Key Vault Managed HSM – Control your data in the cloud - Microsoft Tech Community)

    2.) No. Once the Key Vault is actually purged it is permanently deleted, and "Purge Protection is designed so that no administrator role or permission can override, disable, or circumvent purge protection."

    Reference:

    What are soft-delete and purge protection

    If you have any further concerns that you would like to discuss, feel free to reach out to me at AzCommunity@microsoft.com ("Attn: Marilee Turscak").

    -

    If the information helped you, please Accept the answer. This will help us as well as others in the community who might be researching similar questions.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Ahsan Munim 25 Reputation points
    2023-03-22T11:02:33.89+00:00

    thanks for the clarification!

    1 person found this answer helpful.
    0 comments No comments