last sync: 2024-Sep-18 17:50:24 UTC

Azure Device Update accounts should use customer-managed key to encrypt data at rest

Azure BuiltIn Policy definition

Source Azure Portal
Display name Azure Device Update accounts should use customer-managed key to encrypt data at rest
Id 43c323f6-0329-4f7c-a19a-6e5a5690d042
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0
Built-in Versioning [Preview]
Category Internet of Things
Microsoft Learn
Description Encryption of data at rest in Azure Device Update with customer-managed key adds a second layer of encryption on top of the default service-managed keys, enables customer control of keys, custom rotation policies, and ability to manage access to data through key access control. Learn more at:https://learn.microsoft.com/azure/iot-hub-device-update/device-update-data-encryption.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
Audit
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.DeviceUpdate/accounts/encryption.keyVaultKeyUri Microsoft.DeviceUpdate accounts properties.encryption.keyVaultKeyUri True False
Rule resource types IF (1)
Microsoft.DeviceUpdate/accounts
Compliance Not a Compliance control
Initiatives usage none
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-10-16 18:01:34 add 43c323f6-0329-4f7c-a19a-6e5a5690d042
JSON compare n/a
JSON
api-version=2021-06-01
EPAC