Double Key Encryption (DKE) is a Microsoft security feature that encrypts Office documents with a symmetric key protected by a Microsoft-managed key and a second key managed by an external service such as CSP Vault.

  • Labels configured in the Microsoft Purview Compliance Portal control Office document encryption.
  • An Azure-registered application provides authentication.
  • DKE keys are stored in an Azure key set in the Cloud Cryptographic Security Platform Vault for Cloud Keys. These keys are stored in the dke_keys key vault, separate from Azure key vaults and managed HSMs. The DKE keys are never uploaded to Azure.

See the required configuration steps below.

To use DKE with CSP Vault, set TLS to TLSv1.2 and TLSv1.3, and set EMS to Do not enforce EMS.