--- title: "Azure Key Vault Bring Your Own Key" slug: "fortanix-dsm-azure-key-vault-byok-bring-your-own-key" updated: 2026-08-27T08:01:43Z published: 2026-08-27T08:01:43Z canonical: "support.fortanix.com/fortanix-dsm-azure-key-vault-byok-bring-your-own-key" --- > ## Documentation Index > Fetch the complete documentation index at: https://support.fortanix.com/llms.txt > Use this file to discover all available pages before exploring further. # Azure Key Vault Bring Your Own Key ## 1.0 Introduction This article describes how to perform Bring Your Own Key (BYOK) lifecycle management in Azure Key Vault (AKV) using Fortanix-Data-Security-Manager (DSM). The Fortanix solution for AKV offers complete BYOK, as explained in this article, as well as Cloud Native Key Management Service (CNKMS) with complete lifecycle management for automation. ## 2.0 Getting Started with Fortanix Cloud Data Control *To understand which solution between CNKMS, BYOK, Bring Your Own KMS or Bring Your Own Encryption (BYOE) is right for you, refer to* [*Fortanix DSM - Cloud Data Control - Getting Started*](/v1/docs/fortanix-dsm-cloud-data-control-getting-started)*.* ## 3.0 Azure Key Vault Group Setup and Cloud Native Key Management *For more information on how to set up an Azure-backed group in Fortanix DSM, refer to* [*Fortanix DSM - Azure Key Vault Group Setup*](/v1/docs/fortanix-dsm-azure-key-vault-cdc-group-setup)*.* *For more information on how to perform native key lifecycle management in Azure Key Vault using Fortanix DSM, refer to* [*Fortanix DSM - Azure Key Vault Cloud Native Key Management*](/v1/docs/fortanix-dsm-azure-key-vault-cloud-native-key-management). ## 4.0 Fortanix Azure BYOK Workflows Overview - **Generate key**: Navigate to a source key in Fortanix DSM and copy the key into an Azure CDC group to create a linked key and a BYOK key in Azure Key Vault. - **Rotate source key:** Rotate the source key that was originally generated in "Fortanix DSM" and click “rotate linked/copied keys”. - **Disable/Enable**: Navigate to the detailed view of the key in the Azure CDC group and disable or enable it from Fortanix DSM. - **Soft key deletion**: Azure will not allow you to natively delete a key directly unless you explicitly schedule it for deletion and the mandatory waiting period expires (you can set it anywhere from 7 to 90 days in Azure Key Vault, with 90 days being the default). Additionally, you can enable “Purge Protection” using Azure to avoid manual Purge of keys. If enabled, a mandatory retention period is enforced for deleted keys. If disabled, the keys can be purged during the retention period (you can set the retention period anywhere from 7 to 90 days in Azure Key Vault, with 90 days being the default). *For more information, refer to* [*Azure Key Vault soft-delete overview*](https://learn.microsoft.com/en-us/azure/key-vault/general/soft-delete-overview)*.* Navigate to the detailed view of an Azure virtual key and in the **AZURE KEY DETAILS** tab, click the link **SOFT DELETE KEY**. ## 5.0 Fortanix DSM Azure KMS Security Objects You can generate a key in a configured Azure KMS (Software-backed or HSM-backed Key Vault). ### 5.1 Bring Your Own Key - Copy Key to Azure Key Vault Use this option when you want to create a key in Fortanix DSM and then import it into the configured Azure Key Vault. The Copy Key to Azure feature allows you to transfer a security object from one Fortanix DSM group to another, including to an Azure CDC Fortanix DSM group. This feature has the following advantages: - Maintains a single source of key material while using/importing that key into various Fortanix DSM groups, where applications may need to use a single key to meet business objectives. - Maintains a link of various copies of the same key material to the source key for the ability to name and rotate keys everywhere, all at once, as well as for audit and tracking purposes. The following action happens during the copy key operation: - A new key will be created in the target group: The new key will have the same key material as the original. - The source key links to the copied keys: There will be a link maintained from all copied keys to the source key. - The source key will also have basic metadata-based information about the linked keys, such as: - Copied by - Date of Copy