About the integration
Microsoft Azure DKE and ESKM
Enterprise Secure Key Manager (ESKM) can be used as an external key manager for Microsoft Double Key Encryption (DKE) to provide enhanced data protection and key control. In this setup, Microsoft manages one encryption key, and the second key is securely stored and managed in ESKM by the organization.
When a user opens DKE-protected content in Microsoft 365, the DKE service connects to ESKM to request access to organization’s key. ESKM authorizes the request and allows decryption only if the organization approves it. This ensures that Microsoft cannot access the protected data without the organizations consent.