purview-customer-key

Installation
SKILL.md

Microsoft Purview Customer Key & Double Key Encryption

Microsoft already encrypts M365 data at rest with Microsoft-managed keys. These additional controls let regulated or sovereignty-sensitive customers hold the keys themselves:

  • Customer Key — customer-supplied root keys (in Azure Key Vault HSM) wrap service data-encryption keys for Exchange, SharePoint, OneDrive, Teams (chats/files), and Purview. Revoke the key → Microsoft can no longer decrypt → service-data path crypto- shredded.
  • Double Key Encryption (DKE) — sensitivity-label-driven client-side encryption where one key is customer-held in a self-hosted key release service. Microsoft never sees that key; service-side features (search, eDiscovery, Copilot) cannot read the content.

This skill covers both — when to use which, the architectures, and the operational realities.

Installs
34
GitHub Stars
173
First Seen
Jun 20, 2026
purview-customer-key — vinayaklatthe/microsoft-security-skills