GuideInformationBusiness ContinuityIT

Check Backup vault lifecycle constraints before enabling customer-managed encryption

The CMK decision affects return to platform keys, supported tiers, and future resource moves.

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

The CMK decision affects return to platform keys, supported tiers, and future resource moves.

Potentially affected

Azure Backup vaults being considered for customer-managed key encryption.

DSE recommendation

Approve the continuing key dependency and vault-movement constraints before enabling CMK encryption.

Source facts

After customer-managed encryption is enabled for a Backup vault, Microsoft does not allow a return to platform-managed keys. Encryption keys or the managed identity can still be changed.

Moving that CMK-encrypted vault across resource groups or subscriptions is unsupported. CMK covers the vault and vault-archive tiers, not the operational tier. If access to the required key is lost and cannot be restored, the stored backup data becomes inaccessible. Microsoft Learn.

Applicability

Confirm that the resource is a Backup vault, identify the protection tiers in use, and review planned resource-group or subscription changes. Assess the full key, identity, permission, and network requirements before selecting the encryption model; this article does not prescribe CMK for every workload.

DSE recommendation

DSE recommends documenting the decision as an ongoing dependency rather than a temporary encryption toggle. Have the backup and key owners approve lifecycle responsibility and the effect on planned moves. Require a specific explanation of the protection scope so operational-tier coverage is not inferred from the vault setting.

Verification

Before production enablement, test the approved configuration with representative backup and restore operations in a suitable environment. Check the recorded resource type, tier, key identity, and authorized recovery procedure. Review the migration plan against the documented restrictions rather than attempting a disruptive move to discover whether it is supported.

Official references

Microsoft Learn: Encrypt backup data in a Backup vault by using customer-managed keys. Source retrieved September 9, 2026.

Primary reference

Review the official source

Encrypt backup data in a Backup vault by using customer-managed keys - Azure Backup | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE