Azure Key Vault - Key Hierarchy

José Miguel Lopez Becerra 21 Reputation points
2021-04-07T09:36:37.967+00:00

Does AKV support key hierarchy?
Say I have the BYOK approach where the customer key is at the very top of the hierarchy. And I want to use it to wrap other keys stored in AKV (say these other keys would be on Level 2, I should have full control of them, and be protected by the root key).

Is that possible?
Something similar to the picture.
The reason: We need the BYOK approach. And (like in the picture), we would like to grant "Account Key" to some resource, but without giving direct access to the root key.

85237-screenshot-2021-04-06-164109.png

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,451 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.