What you need to know
When can the previous key version be retired after Recovery Services vault key autorotation?
Potentially affected
Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.
DSE recommendation
Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement.
Source facts
For a Recovery Services vault using customer-managed encryption, selecting a key through the Key Vault picker enables automatic version rotation. A complete key URI containing a version instead requires manual updates; removing that version component enables autorotation. The new version can take up to an hour to become effective. Microsoft requires the previous version to remain enabled for at least one subsequent backup job after that change takes effect. Microsoft Learn.
Applicability
Apply this review to an existing customer-managed-key Recovery Services vault, not to an initial encryption migration. Identify the configured key reference, key-management interface, and actual rotation owner before scheduling retirement.
DSE recommendation
Make old-key retirement a separate approved step with evidence, not an automatic companion to creating the replacement. Record the previous and intended key-version identifiers without exporting key material. Agree who will observe the effective vault update and the following backup job. Keep the earlier version available while those observations are incomplete, and investigate a delayed update before changing access or disabling keys.
Verification
In an approved rotation exercise, inspect the effective encryption configuration and corresponding backup result. Confirm that the evidence refers to a job after the update, rather than an earlier successful job. Record the retirement decision separately and verify a representative recovery through the authorized process. Do not claim success solely because a new version exists in Key Vault.
Official references
Microsoft Learn: Encrypt backup data by using customer-managed keys.
Review the official source
Encrypt backup data by using customer-managed keys - Azure Backup | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE