purview-customer-key
Installation
SKILL.md
Microsoft Purview Customer Key & Double Key Encryption
Microsoft already encrypts M365 data at rest with Microsoft-managed keys. These additional controls let regulated or sovereignty-sensitive customers hold the keys themselves:
- Customer Key — customer-supplied root keys (in Azure Key Vault HSM) wrap service data-encryption keys for Exchange, SharePoint, OneDrive, Teams (chats/files), and Purview. Revoke the key → Microsoft can no longer decrypt → service-data path crypto- shredded.
- Double Key Encryption (DKE) — sensitivity-label-driven client-side encryption where one key is customer-held in a self-hosted key release service. Microsoft never sees that key; service-side features (search, eDiscovery, Copilot) cannot read the content.
This skill covers both — when to use which, the architectures, and the operational realities.