What is the frequency of key rotation in Platform Managed Keys

BryanW 35 Reputation points
2023-05-17T14:29:31.1366667+00:00

Hello,

I understand that Azure provides a facility to encrypt data-at-rest using Platform Managed Keys (PMKs). My question is: what is frequency of key rotation for PMK?

I have an audit request for this and would like to know how often the key is rotated.

Thank you.

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
{count} votes

Accepted answer
  1. KarishmaTiwari-MSFT 18,647 Reputation points Microsoft Employee
    2023-05-24T03:36:35.2933333+00:00

    @BryanW

    Update 5/23/2023:
    I reached out to the Product team to see if I can get more information on the key rotation frequency for PMK.
    They confirmed that- no mention of it in the public documentation is intentional.

    There are no plans to share this information publicly. It is a "security by obscurity" scenario. If it is a requirement for customers to have control on the rotation frequency, their recommendation is to use Customer Managed Keys. I hope that helps.

    5/18/2023 (Summary from the comment above):

    Unfortunately, the exact frequency of key rotation for PMKs in Azure cannot be publicly disclosed.
    There is no mention of it in any public documentation.
    User's image

    However, it is worth noting that Azure offers several options for storing and managing your keys in the cloud, including Azure Key Vault, which allows you to configure key rotation policies for customer-managed keys. You can set a rotation policy to automatically generate a new key version at a specified frequency.

    The rotation frequency for DEKs in Azure Disk Encryption can be determined by the user/administrator based on their specific requirements. Our recommendation is to rotate encryption keys at least every two years to meet cryptographic best practices.

    Reference documentation: https://learn.microsoft.com/en-us/azure/virtual-machines/disk-encryption#about-encryption-key-management


    If you have any other questions, please let us know in the "comments" and we would be happy to help you. Comment is the fastest way of notifying the experts.

    Please don’t forget to Accept Answer and hit Yes for "was this answer helpful" wherever the information provided helps you. This can be beneficial to other community members for remediation for similar issues.

    User's image

    4 people found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful