Skip to content

Commit 5bb8370

Browse files
committed
Adding PMK section.
1 parent c018232 commit 5bb8370

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

articles/storage/elastic-san/elastic-san-encryption-overview.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,10 @@ Two kinds of encryption keys are available: platform-managed keys and customer-m
2323

2424
When you configure a volume group, you can choose to use either platform-managed or customer-managed keys. All volumes in a volume group inherit the volume group's configuration. You can switch between customer-managed and platform-managed keys at any time. If you switch between these key types, the Elastic SAN service re-encrypts the data encryption key by using the new KEK. The protection of the data encryption key changes, but the data in your Elastic SAN volumes always remains encrypted. You don't need to take any extra action to ensure that your data is protected.
2525

26+
## Platform-managed keys
27+
28+
By default, Azure Elastic SAN uses plat-form managed encryption keys. All Elastic SANs and their underlying resources and data are automatically encrypted-at-rest with platform-managed keys. Platform-managed keys are managed by Microsoft.
29+
2630
## Customer-managed keys
2731

2832
If you use customer-managed keys, you must use an [Azure Key Vault](/azure/key-vault/general/overview) to store the key.

0 commit comments

Comments
 (0)