Skip to main content
security · azure

Storage accounts encrypting data with Microsoft-managed keys instead of a key you control

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure Storage account whose encryption key source is `Microsoft.Storage`, meaning Microsoft-managed keys, rather than `Microsoft.Keyvault` with a customer-managed key. Storage encryption itself is always on with 256-bit AES; this finding is about who owns and can revoke the key, which many compliance frameworks require.

Signal and threshold

How ZopNight evaluates Storage accounts encrypting data with Microsoft-managed keys instead of a key you control.
Field Value
Rule IDsRC-1321
Categorysecurity
Severitymedium
Metricnone — pure configuration read
Thresholdencryption key source is not Microsoft.Keyvault
SourceZopNight
Permissions usedMicrosoft.Storage/storageAccounts/read

Encryption is on either way; the question is who holds the key

Every storage account is encrypted at rest. The storage encryption overview says Azure Storage encryption uses 256-bit AES, is enabled for all accounts, and cannot be disabled. New accounts use Microsoft-managed keys by default, which Microsoft rotates according to its own compliance requirements.

What changes with a customer-managed key is control. The customer-managed keys overview explains that Azure Storage wraps the account’s root encryption key with your key in Azure Key Vault or Key Vault Managed HSM. You decide when the key rotates, and disabling the key revokes access: reads and writes then fail with a 403 error until you restore it. Frameworks that ask for customer control over encryption keys are looking for exactly this.

Listing the key source of each account

Terminal window
az storage account list \
--query "[].{name:name, rg:resourceGroup, keySource:encryption.keySource, infraEncryption:encryption.requireInfrastructureEncryption}" \
-o table

Microsoft.Storage means Microsoft-managed keys; Microsoft.Keyvault means a customer-managed key.

The single setting this check reads

ZopNight reads the account’s encryption key source and raises a finding only when it is present and is not Microsoft.Keyvault. The recommendation also reports whether infrastructure encryption, a second layer of encryption at the infrastructure level, is on, as supporting evidence. That value does not affect whether the finding is raised.

Accounts with no finding

Accounts already on a customer-managed key are compliant. When the key source cannot be read, the account is not flagged; ZopNight does not treat missing data as a failure. This rule does not judge encryption scopes set on individual containers, only the account-level key.

A compliance finding with no dollar figure

There is no saving here and none is shown. Moving to a customer-managed key adds work rather than removing cost: a key vault to run, a key rotation process, and a managed identity to keep healthy. The value is audit evidence and the ability to revoke access to the data yourself.

Switching the account to a customer-managed key

  1. Prepare a key vault or Managed HSM that meets Microsoft’s requirements: soft delete and purge protection enabled, and an RSA or RSA-HSM key of 2048, 3072 or 4096 bits.
  2. Give the account’s managed identity at least the get, wrapkey and unwrapkey key permissions.
  3. Point the account at the key, for example az storage account update --resource-group my-rg --name mystorageacct --encryption-key-source Microsoft.Keyvault --encryption-key-vault https://my-vault.vault.azure.net --encryption-key-name my-key --key-vault-user-identity-id <identity-resource-id>.
  4. Confirm the key source now reads Microsoft.Keyvault.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·