Double Key Encryption (DKE) is a Microsoft security feature that encrypts Office documents with a symmetric key protected by a Microsoft-managed key and a second key managed by an external service such as CSP Vault.
- Labels configured in the Microsoft Purview Compliance Portal control Office document encryption.
- An Azure-registered application provides authentication.
- DKE keys are stored in an Azure key set in the Cloud Cryptographic Security Platform Vault for Cloud Keys. These keys are stored in the dke_keys key vault, separate from Azure key vaults and managed HSMs. The DKE keys are never uploaded to Azure.
See the required configuration steps below.
- CSP Vault prerequisites for DKE
- Creating a key set for DKE
- Creating a CloudKey for DKE
- Viewing CloudKey details
- Creating compliance labels
- Using compliance labels with MS Office
- Register with Azure Entra
To use DKE with CSP Vault, set TLS to TLSv1.2 and TLSv1.3, and set EMS to Do not enforce EMS.