# Reestablish Key Vault autorotation settings after regional recreation

> Does a successful Key Vault backup and restore carry the source vault's autorotation configuration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-401-reestablish-key-vault-autorotation-settings-after-regional-recreation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:15+00:00
- Modified: 2026-09-10T02:04:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Cybersecurity
- Reading time: 2 minutes

## What you need to know

Does a successful Key Vault backup and restore carry the source vault's autorotation configuration?

## Potentially affected

Azure Key Vault regional recreation and supported backup/restore workflows.

## DSE recommendation

DSE recommends recording the source's intended rotation configuration before creating the target vault.

## Article

## Source facts

Azure Key Vault does not provide an in-place regional relocation. Microsoft’s approach creates a new vault alongside the associated services’ relocation. Backup and restore do not retain autorotation settings. The target vault also requires its access, network, soft-delete and purge-protection configuration to be reestablished. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-key-vault).

## Applicability

Use this check as part of a regional recreation plan, not as permission to copy a key between arbitrary locations. Have the vault owner verify the applicable object-transfer method and geography constraints before relying on backup and restore. Separate the object inventory from its continuing rotation configuration.

## DSE recommendation

DSE recommends recording the source’s intended rotation configuration before creating the target vault. Compare the target settings against that record after the supported object-transfer or regeneration process. Assign ownership for any deliberate difference rather than treating the presence of the expected keys as proof that their maintenance policy survived. Review application references and required access with the relevant service owners before cutover.

## Verification

Inspect the target vault’s actual rotation configuration and required objects independently. Use an approved test object and consumer to evaluate the intended ongoing process without rotating production material merely to collect evidence. Preserve the configuration comparison and unresolved exceptions. Keep retirement of the source vault as a separate decision until the migration owner has verified the required objects, settings and consumer access.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-key-vault). Source retrieved September 9, 2026.

## Primary reference

- Name: Relocate Azure Key Vault to another region - Azure Resource Manager | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-key-vault
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Reestablish Key Vault autorotation settings after regional recreation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-401-reestablish-key-vault-autorotation-settings-after-regional-recreation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
