{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
        "slug": "dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/"
        },
        "title": "Keep the prior Recovery Services encryption key available through rotation",
        "summary": "When can the previous key version be retired after Recovery Services vault key autorotation?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:24+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 238,
        "potentially_affected": "Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.",
        "dse_recommendation": "Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement.",
        "primary_source": {
            "name": "Encrypt backup data by using customer-managed keys - Azure Backup | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. <a href=\"https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.</p>\n<h2>DSE recommendation</h2>\n<p>Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.</p>\n<h2>Verification</h2>\n<p>In an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Encrypt backup data by using customer-managed keys</a>.</p>",
        "content_text": "Source facts\nFor a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. Microsoft Learn.\nApplicability\nApply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.\nDSE recommendation\nMake old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.\nVerification\nIn an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.\nOfficial references\nMicrosoft Learn: Encrypt backup data by using customer-managed keys.",
        "content_markdown": "## Source facts\n\nFor a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk).\n\n## Applicability\n\nApply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.\n\n## DSE recommendation\n\nMake old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.\n\n## Verification\n\nIn an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.\n\n## Official references\n\n[Microsoft Learn: Encrypt backup data by using customer-managed keys](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep the prior Recovery Services encryption key available through rotation",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/",
                "headline": "Keep the prior Recovery Services encryption key available through rotation",
                "description": "When can the previous key version be retired after Recovery Services vault key autorotation?",
                "abstract": "When can the previous key version be retired after Recovery Services vault key autorotation?",
                "articleBody": "Source facts\nFor a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. Microsoft Learn.\nApplicability\nApply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.\nDSE recommendation\nMake old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.\nVerification\nIn an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.\nOfficial references\nMicrosoft Learn: Encrypt backup data by using customer-managed keys.",
                "datePublished": "2026-09-10T00:24:24+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep the prior Recovery Services encryption key available through rotation"
                },
                "articleSection": [
                    "Business Continuity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Business Continuity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 238,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Encrypt backup data by using customer-managed keys - Azure Backup | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk"
                }
            }
        ]
    }
}