# Keep the prior Recovery Services encryption key available through rotation

> When can the previous key version be retired after Recovery Services vault key autorotation?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:24+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

When can the previous key version be retired after Recovery Services vault key autorotation?

## Potentially affected

Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.

## DSE recommendation

Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement.

## Article

## Source facts

For a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk).

## Applicability

Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.

## DSE recommendation

Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.

## Verification

In an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.

## Official references

[Microsoft Learn: Encrypt backup data by using customer-managed keys](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk).

## Primary reference

- Name: Encrypt backup data by using customer-managed keys - Azure Backup | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep the prior Recovery Services encryption key available through rotation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-452-keep-the-prior-recovery-services-encryption-key-available-through-rotation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
