Skip to content

Commit 3cfbec8

Browse files
Merge pull request #307220 from guywi-ms/cmk-update-transition
Update move-to-defender.md
2 parents 44e6f3a + 58d3816 commit 3cfbec8

1 file changed

Lines changed: 8 additions & 2 deletions

File tree

articles/sentinel/move-to-defender.md

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -66,9 +66,15 @@ For more information, see:
6666

6767
### Onboarding to the Defender portal with customer-managed keys (CMK)
6868

69-
If you onboard your Microsoft Sentinel-enabled workspace to the Defender portal, ingested workspace data/logs remain encrypted with CMK. Other data isn't encrypted with CMK and uses a Microsoft-managed key.
69+
If you enabled CMK before onboarding, when you onboard your Microsoft Sentinel-enabled workspace to the Defender portal, all log data in your workspace continues to be encrypted with CMK - including both previously and newly ingested data.
70+
71+
Analytic rules and other Sentinel content, such as automation rules, also continue to be CMK-encrypted. However, alerts and incidents will no longer be CMK-encrypted after onboarding.
72+
73+
For more information about CMK, see [Set up Microsoft Sentinel customer-managed key](customer-managed-keys.md).
74+
75+
> [!IMPORTANT]
76+
> CMK encryption is not fully supported for data stored in the Microsoft Sentinel data lake. All data ingested into the data lake - such as custom tables or transformed data - is encrypted using Microsoft-managed keys.
7077
71-
For more information, see [Set up Microsoft Sentinel customer-managed key](customer-managed-keys.md).
7278

7379
### Configure multi-workspace and multitenant management
7480

0 commit comments

Comments
 (0)