# Check Backup vault lifecycle constraints before enabling customer-managed encryption

> The CMK decision affects return to platform keys, supported tiers, and future resource moves.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-472-check-backup-vault-lifecycle-constraints-before-enabling-customer-managed/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:04+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

The CMK decision affects return to platform keys, supported tiers, and future resource moves.

## Potentially affected

Azure Backup vaults being considered for customer-managed key encryption.

## DSE recommendation

Approve the continuing key dependency and vault-movement constraints before enabling CMK encryption.

## Article

## Source facts

After customer-managed encryption is enabled for a Backup vault, Microsoft does not allow a return to platform-managed keys. Encryption keys or the managed identity can still be changed.

Moving that CMK-encrypted vault across resource groups or subscriptions is unsupported. CMK covers the vault and vault-archive tiers, not the operational tier. If access to the required key is lost and cannot be restored, the stored backup data becomes inaccessible. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk-for-backup-vault).

## Applicability

Confirm that the resource is a Backup vault, identify the protection tiers in use, and review planned resource-group or subscription changes. Assess the full key, identity, permission, and network requirements before selecting the encryption model; this article does not prescribe CMK for every workload.

## DSE recommendation

DSE recommends documenting the decision as an ongoing dependency rather than a temporary encryption toggle. Have the backup and key owners approve lifecycle responsibility and the effect on planned moves. Require a specific explanation of the protection scope so operational-tier coverage is not inferred from the vault setting.

## Verification

Before production enablement, test the approved configuration with representative backup and restore operations in a suitable environment. Check the recorded resource type, tier, key identity, and authorized recovery procedure. Review the migration plan against the documented restrictions rather than attempting a disruptive move to discover whether it is supported.

## Official references

[Microsoft Learn: Encrypt backup data in a Backup vault by using customer-managed keys](https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk-for-backup-vault). Source retrieved September 9, 2026.

## Primary reference

- Name: Encrypt backup data in a Backup vault by using customer-managed keys - Azure Backup | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/backup/encryption-at-rest-with-cmk-for-backup-vault
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Backup vault lifecycle constraints before enabling customer-managed encryption,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-472-check-backup-vault-lifecycle-constraints-before-enabling-customer-managed/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
